directory 구조 변경
This commit is contained in:
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Principal": { "Service": "ec2.amazonaws.com"},
|
||||
"Action": "sts:AssumeRole"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Principal": { "Service": "ec2.amazonaws.com"},
|
||||
"Action": "sts:AssumeRole"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,259 @@
|
||||
{
|
||||
"Statement": [
|
||||
{
|
||||
"Action": "ec2:AttachVolume",
|
||||
"Condition": {
|
||||
"StringEquals": {
|
||||
"aws:ResourceTag/KubernetesCluster": "dev.datasaker.io",
|
||||
"aws:ResourceTag/k8s.io/role/master": "1"
|
||||
}
|
||||
},
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"s3:Get*"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": "arn:aws:s3:::clusters.dev.datasaker.io/dev.datasaker.io/*"
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"s3:GetObject",
|
||||
"s3:DeleteObject",
|
||||
"s3:DeleteObjectVersion",
|
||||
"s3:PutObject"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": "arn:aws:s3:::clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/main/*"
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"s3:GetObject",
|
||||
"s3:DeleteObject",
|
||||
"s3:DeleteObjectVersion",
|
||||
"s3:PutObject"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": "arn:aws:s3:::clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/events/*"
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"s3:GetBucketLocation",
|
||||
"s3:GetEncryptionConfiguration",
|
||||
"s3:ListBucket",
|
||||
"s3:ListBucketVersions"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:s3:::clusters.dev.datasaker.io"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"route53:ChangeResourceRecordSets",
|
||||
"route53:ListResourceRecordSets",
|
||||
"route53:GetHostedZone"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:route53:::hostedzone/Z072735718G25WNVKU834"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"route53:GetChange"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:route53:::change/*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"route53:ListHostedZones",
|
||||
"route53:ListTagsForResource"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": "ec2:CreateTags",
|
||||
"Condition": {
|
||||
"StringEquals": {
|
||||
"aws:RequestTag/KubernetesCluster": "dev.datasaker.io",
|
||||
"ec2:CreateAction": [
|
||||
"CreateVolume",
|
||||
"CreateSnapshot"
|
||||
]
|
||||
}
|
||||
},
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:ec2:*:*:volume/*",
|
||||
"arn:aws:ec2:*:*:snapshot/*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"ec2:CreateTags",
|
||||
"ec2:DeleteTags"
|
||||
],
|
||||
"Condition": {
|
||||
"Null": {
|
||||
"aws:RequestTag/KubernetesCluster": "true"
|
||||
},
|
||||
"StringEquals": {
|
||||
"aws:ResourceTag/KubernetesCluster": "dev.datasaker.io"
|
||||
}
|
||||
},
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:ec2:*:*:volume/*",
|
||||
"arn:aws:ec2:*:*:snapshot/*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": "ec2:CreateTags",
|
||||
"Condition": {
|
||||
"StringEquals": {
|
||||
"aws:RequestTag/KubernetesCluster": "dev.datasaker.io",
|
||||
"ec2:CreateAction": [
|
||||
"CreateSecurityGroup"
|
||||
]
|
||||
}
|
||||
},
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:ec2:*:*:security-group/*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"ec2:CreateTags",
|
||||
"ec2:DeleteTags"
|
||||
],
|
||||
"Condition": {
|
||||
"Null": {
|
||||
"aws:RequestTag/KubernetesCluster": "true"
|
||||
},
|
||||
"StringEquals": {
|
||||
"aws:ResourceTag/KubernetesCluster": "dev.datasaker.io"
|
||||
}
|
||||
},
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:ec2:*:*:security-group/*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"autoscaling:DescribeAutoScalingGroups",
|
||||
"autoscaling:DescribeAutoScalingInstances",
|
||||
"autoscaling:DescribeLaunchConfigurations",
|
||||
"autoscaling:DescribeTags",
|
||||
"ec2:DescribeAccountAttributes",
|
||||
"ec2:DescribeInstanceTypes",
|
||||
"ec2:DescribeInstances",
|
||||
"ec2:DescribeLaunchTemplateVersions",
|
||||
"ec2:DescribeRegions",
|
||||
"ec2:DescribeRouteTables",
|
||||
"ec2:DescribeSecurityGroups",
|
||||
"ec2:DescribeSubnets",
|
||||
"ec2:DescribeTags",
|
||||
"ec2:DescribeVolumes",
|
||||
"ec2:DescribeVolumesModifications",
|
||||
"ec2:DescribeVpcs",
|
||||
"ec2:ModifyNetworkInterfaceAttribute",
|
||||
"ecr:BatchCheckLayerAvailability",
|
||||
"ecr:BatchGetImage",
|
||||
"ecr:DescribeRepositories",
|
||||
"ecr:GetAuthorizationToken",
|
||||
"ecr:GetDownloadUrlForLayer",
|
||||
"ecr:GetRepositoryPolicy",
|
||||
"ecr:ListImages",
|
||||
"elasticloadbalancing:DescribeListeners",
|
||||
"elasticloadbalancing:DescribeLoadBalancerAttributes",
|
||||
"elasticloadbalancing:DescribeLoadBalancerPolicies",
|
||||
"elasticloadbalancing:DescribeLoadBalancers",
|
||||
"elasticloadbalancing:DescribeTargetGroups",
|
||||
"elasticloadbalancing:DescribeTargetHealth",
|
||||
"iam:GetServerCertificate",
|
||||
"iam:ListServerCertificates",
|
||||
"kms:DescribeKey",
|
||||
"kms:GenerateRandom"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": "*"
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"autoscaling:SetDesiredCapacity",
|
||||
"autoscaling:TerminateInstanceInAutoScalingGroup",
|
||||
"ec2:AttachVolume",
|
||||
"ec2:AuthorizeSecurityGroupIngress",
|
||||
"ec2:DeleteSecurityGroup",
|
||||
"ec2:DeleteVolume",
|
||||
"ec2:DetachVolume",
|
||||
"ec2:ModifyInstanceAttribute",
|
||||
"ec2:ModifyVolume",
|
||||
"ec2:RevokeSecurityGroupIngress",
|
||||
"elasticloadbalancing:AddTags",
|
||||
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
|
||||
"elasticloadbalancing:AttachLoadBalancerToSubnets",
|
||||
"elasticloadbalancing:ConfigureHealthCheck",
|
||||
"elasticloadbalancing:CreateLoadBalancerListeners",
|
||||
"elasticloadbalancing:CreateLoadBalancerPolicy",
|
||||
"elasticloadbalancing:DeleteListener",
|
||||
"elasticloadbalancing:DeleteLoadBalancer",
|
||||
"elasticloadbalancing:DeleteLoadBalancerListeners",
|
||||
"elasticloadbalancing:DeleteTargetGroup",
|
||||
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
|
||||
"elasticloadbalancing:DeregisterTargets",
|
||||
"elasticloadbalancing:DetachLoadBalancerFromSubnets",
|
||||
"elasticloadbalancing:ModifyListener",
|
||||
"elasticloadbalancing:ModifyLoadBalancerAttributes",
|
||||
"elasticloadbalancing:ModifyTargetGroup",
|
||||
"elasticloadbalancing:RegisterInstancesWithLoadBalancer",
|
||||
"elasticloadbalancing:RegisterTargets",
|
||||
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
|
||||
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener"
|
||||
],
|
||||
"Condition": {
|
||||
"StringEquals": {
|
||||
"aws:ResourceTag/KubernetesCluster": "dev.datasaker.io"
|
||||
}
|
||||
},
|
||||
"Effect": "Allow",
|
||||
"Resource": "*"
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"ec2:CreateSecurityGroup",
|
||||
"ec2:CreateSnapshot",
|
||||
"ec2:CreateVolume",
|
||||
"elasticloadbalancing:CreateListener",
|
||||
"elasticloadbalancing:CreateLoadBalancer",
|
||||
"elasticloadbalancing:CreateTargetGroup"
|
||||
],
|
||||
"Condition": {
|
||||
"StringEquals": {
|
||||
"aws:RequestTag/KubernetesCluster": "dev.datasaker.io"
|
||||
}
|
||||
},
|
||||
"Effect": "Allow",
|
||||
"Resource": "*"
|
||||
},
|
||||
{
|
||||
"Action": "ec2:CreateSecurityGroup",
|
||||
"Effect": "Allow",
|
||||
"Resource": "arn:aws:ec2:*:*:vpc/*"
|
||||
}
|
||||
],
|
||||
"Version": "2012-10-17"
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
{
|
||||
"Statement": [
|
||||
{
|
||||
"Action": [
|
||||
"s3:Get*"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:s3:::clusters.dev.datasaker.io/dev.datasaker.io/addons/*",
|
||||
"arn:aws:s3:::clusters.dev.datasaker.io/dev.datasaker.io/cluster-completed.spec",
|
||||
"arn:aws:s3:::clusters.dev.datasaker.io/dev.datasaker.io/igconfig/node/*",
|
||||
"arn:aws:s3:::clusters.dev.datasaker.io/dev.datasaker.io/secrets/dockerconfig"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"s3:GetBucketLocation",
|
||||
"s3:GetEncryptionConfiguration",
|
||||
"s3:ListBucket",
|
||||
"s3:ListBucketVersions"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": [
|
||||
"arn:aws:s3:::clusters.dev.datasaker.io"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Action": [
|
||||
"autoscaling:DescribeAutoScalingInstances",
|
||||
"ec2:DescribeInstanceTypes",
|
||||
"ec2:DescribeInstances",
|
||||
"ec2:DescribeRegions",
|
||||
"ec2:ModifyNetworkInterfaceAttribute",
|
||||
"ecr:BatchCheckLayerAvailability",
|
||||
"ecr:BatchGetImage",
|
||||
"ecr:DescribeRepositories",
|
||||
"ecr:GetAuthorizationToken",
|
||||
"ecr:GetDownloadUrlForLayer",
|
||||
"ecr:GetRepositoryPolicy",
|
||||
"ecr:ListImages",
|
||||
"iam:GetServerCertificate",
|
||||
"iam:ListServerCertificates",
|
||||
"kms:GenerateRandom"
|
||||
],
|
||||
"Effect": "Allow",
|
||||
"Resource": "*"
|
||||
}
|
||||
],
|
||||
"Version": "2012-10-17"
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCyfTPnCyr0Typ7yGTcy0LEGa8IH8yESEXa4Qyr85dWrxazTnWO7iYS0Ze6L0GMMO5qZXg/ntJGhI4PYF/WbCZ5KZMRXePyQIVs5pKMvSX4yH2gPIET5c6yTg4ZSIqrZDLBXGEZxMVp/SnNx1tRzxi0plBDtguSy6LZD0C1ue+VeT4oO98EB2T01GOeQp+RlF/theZuEWSWOVfFD0qVdsHIwVlYYlEZR11IrTamabMOVzyw+/8cokA4hgsrrkSrpKQ2YW0evHK1pxZrw+i3YJuHh3hJ0h98Ymw3rpHGec59gXaYT0PQEQvZs9RCrYw8NpCTQrImXR1UVjeeY3KGgpYQXna+WAmkjA+K/JvLmHGeombVJyd3v8330FX+Ob9klgqTWFvwb8Ew4QCcfl5hDAWxvzoJKAoG/TAZd13aNYaZAVkeWB7vPFWZ0brea6sqUJzXqzPwUXa0OirnqEfxMLZoo4tFyfxuVYVK+ScxayBPYJQkhwmTAZ4bj0OfQEw/jJM= hsgahm@ws-ubuntu
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-data-druid-a
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: i8ZU3JYn4ky+JMWbd5o6SGd8pQX2T2Js/GJVM4ELTMY=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-data-druid-b
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: zKG8laSZLKUofsgCmpTkjq/wM804eIkMHGX+BShf8Xk=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-data-druid-c
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: YhiWkxZTwUsYQwl0HRo682ku6OjJiay8SNHD4Ai2RDo=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-data-kafka-a
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: DKAdNBi89Hg/K4/++jF/gCUMxV0IzUKiyjnFAvhnWHg=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-data-kafka-b
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: G3nQuQTQuU0v5JRMfVZywJVUZxZGBIELTfwxmUeEKlc=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-data-kafka-c
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: zcqf9y8BDn/MuYepBtfh/+13fWsk+LzhH98DXYXKSaQ=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-mgmt-a
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: /7AvbMZe7bqnvkFDqaaD58JLNpSdFz2YBV7bicn9SBU=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-mgmt-b
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: 1bim3y49H61m6xqaMNmZ7FJaqPQ7bhobuaKlBbsK4Io=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-mgmt-c
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: ARAislI0qz2jhFUF8yatW1ITTWXRkY9Sxc25BBt77Vw=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-process-a
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: xmkzEMYRSeEptG16cJUXqjf+kA09Jt09sDchuhwQxyA=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-process-b
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: ILasOIasBRTzHAYQV7G3YTw6QKD/vKU+7qgAPRWT/fs=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,192 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: dev-process-c
|
||||
InstanceGroupRole: Node
|
||||
NodeupConfigHash: KPtyTPA//J5si06n+qNL/6sozOWSO372LH6NtCxyMPA=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,290 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
encryptionConfig: null
|
||||
etcdClusters:
|
||||
events:
|
||||
cpuRequest: 100m
|
||||
memoryRequest: 100Mi
|
||||
version: 3.5.4
|
||||
main:
|
||||
cpuRequest: 200m
|
||||
memoryRequest: 100Mi
|
||||
version: 3.5.4
|
||||
kubeAPIServer:
|
||||
allowPrivileged: true
|
||||
anonymousAuth: false
|
||||
apiAudiences:
|
||||
- kubernetes.svc.default
|
||||
apiServerCount: 3
|
||||
authorizationMode: Node,RBAC
|
||||
bindAddress: 0.0.0.0
|
||||
cloudProvider: external
|
||||
enableAdmissionPlugins:
|
||||
- NamespaceLifecycle
|
||||
- LimitRanger
|
||||
- ServiceAccount
|
||||
- DefaultStorageClass
|
||||
- DefaultTolerationSeconds
|
||||
- MutatingAdmissionWebhook
|
||||
- ValidatingAdmissionWebhook
|
||||
- NodeRestriction
|
||||
- ResourceQuota
|
||||
etcdServers:
|
||||
- https://127.0.0.1:4001
|
||||
etcdServersOverrides:
|
||||
- /events#https://127.0.0.1:4002
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-apiserver:v1.25.2@sha256:86e7b79379dddf58d7b7189d02ca96cc7e07d18efa4eb42adcaa4cf94531b96e
|
||||
kubeletPreferredAddressTypes:
|
||||
- InternalIP
|
||||
- Hostname
|
||||
- ExternalIP
|
||||
logLevel: 2
|
||||
requestheaderAllowedNames:
|
||||
- aggregator
|
||||
requestheaderExtraHeaderPrefixes:
|
||||
- X-Remote-Extra-
|
||||
requestheaderGroupHeaders:
|
||||
- X-Remote-Group
|
||||
requestheaderUsernameHeaders:
|
||||
- X-Remote-User
|
||||
securePort: 443
|
||||
serviceAccountIssuer: https://api.internal.dev.datasaker.io
|
||||
serviceAccountJWKSURI: https://api.internal.dev.datasaker.io/openid/v1/jwks
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
storageBackend: etcd3
|
||||
kubeControllerManager:
|
||||
allocateNodeCIDRs: true
|
||||
attachDetachReconcileSyncPeriod: 1m0s
|
||||
cloudProvider: external
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
clusterName: dev.datasaker.io
|
||||
configureCloudRoutes: false
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-controller-manager:v1.25.2@sha256:f961aee35fd2e9a5ee057365e56c5bf40a39bfef91f785f312e51891db41876b
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
useServiceAccountCredentials: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubeScheduler:
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-scheduler:v1.25.2@sha256:ef2e24a920a7432aff5b435562301dde3beb528b0c7bbec58ddf0a9af64d5fce
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
masterKubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
registerSchedulable: false
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: master-ap-northeast-2a
|
||||
InstanceGroupRole: Master
|
||||
NodeupConfigHash: qan0mo1KY5Q5p8aQ+/k3sCUBKhwzY63cGLMWRd4Mcnc=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,290 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
encryptionConfig: null
|
||||
etcdClusters:
|
||||
events:
|
||||
cpuRequest: 100m
|
||||
memoryRequest: 100Mi
|
||||
version: 3.5.4
|
||||
main:
|
||||
cpuRequest: 200m
|
||||
memoryRequest: 100Mi
|
||||
version: 3.5.4
|
||||
kubeAPIServer:
|
||||
allowPrivileged: true
|
||||
anonymousAuth: false
|
||||
apiAudiences:
|
||||
- kubernetes.svc.default
|
||||
apiServerCount: 3
|
||||
authorizationMode: Node,RBAC
|
||||
bindAddress: 0.0.0.0
|
||||
cloudProvider: external
|
||||
enableAdmissionPlugins:
|
||||
- NamespaceLifecycle
|
||||
- LimitRanger
|
||||
- ServiceAccount
|
||||
- DefaultStorageClass
|
||||
- DefaultTolerationSeconds
|
||||
- MutatingAdmissionWebhook
|
||||
- ValidatingAdmissionWebhook
|
||||
- NodeRestriction
|
||||
- ResourceQuota
|
||||
etcdServers:
|
||||
- https://127.0.0.1:4001
|
||||
etcdServersOverrides:
|
||||
- /events#https://127.0.0.1:4002
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-apiserver:v1.25.2@sha256:86e7b79379dddf58d7b7189d02ca96cc7e07d18efa4eb42adcaa4cf94531b96e
|
||||
kubeletPreferredAddressTypes:
|
||||
- InternalIP
|
||||
- Hostname
|
||||
- ExternalIP
|
||||
logLevel: 2
|
||||
requestheaderAllowedNames:
|
||||
- aggregator
|
||||
requestheaderExtraHeaderPrefixes:
|
||||
- X-Remote-Extra-
|
||||
requestheaderGroupHeaders:
|
||||
- X-Remote-Group
|
||||
requestheaderUsernameHeaders:
|
||||
- X-Remote-User
|
||||
securePort: 443
|
||||
serviceAccountIssuer: https://api.internal.dev.datasaker.io
|
||||
serviceAccountJWKSURI: https://api.internal.dev.datasaker.io/openid/v1/jwks
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
storageBackend: etcd3
|
||||
kubeControllerManager:
|
||||
allocateNodeCIDRs: true
|
||||
attachDetachReconcileSyncPeriod: 1m0s
|
||||
cloudProvider: external
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
clusterName: dev.datasaker.io
|
||||
configureCloudRoutes: false
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-controller-manager:v1.25.2@sha256:f961aee35fd2e9a5ee057365e56c5bf40a39bfef91f785f312e51891db41876b
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
useServiceAccountCredentials: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubeScheduler:
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-scheduler:v1.25.2@sha256:ef2e24a920a7432aff5b435562301dde3beb528b0c7bbec58ddf0a9af64d5fce
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
masterKubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
registerSchedulable: false
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: master-ap-northeast-2b
|
||||
InstanceGroupRole: Master
|
||||
NodeupConfigHash: VE3SMVuK4n6CDYK1kIill+w/93F5DHPTsu1BDc0qBFg=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,290 @@
|
||||
#!/bin/bash
|
||||
set -o errexit
|
||||
set -o nounset
|
||||
set -o pipefail
|
||||
|
||||
NODEUP_URL_AMD64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-amd64
|
||||
NODEUP_HASH_AMD64=3f080d73908f1263c9754f114042f8a934c2239c17bc73b04a2f84c64ec4f68f
|
||||
NODEUP_URL_ARM64=https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/nodeup,https://github.com/kubernetes/kops/releases/download/v1.25.0/nodeup-linux-arm64
|
||||
NODEUP_HASH_ARM64=4a906834670bd86b5a3256aa1bba81c2d3aee5ff440e723a048fa832b336487c
|
||||
|
||||
export AWS_REGION=ap-northeast-2
|
||||
|
||||
|
||||
|
||||
|
||||
sysctl -w net.core.rmem_max=16777216 || true
|
||||
sysctl -w net.core.wmem_max=16777216 || true
|
||||
sysctl -w net.ipv4.tcp_rmem='4096 87380 16777216' || true
|
||||
sysctl -w net.ipv4.tcp_wmem='4096 87380 16777216' || true
|
||||
|
||||
|
||||
function ensure-install-dir() {
|
||||
INSTALL_DIR="/opt/kops"
|
||||
# On ContainerOS, we install under /var/lib/toolbox; /opt is ro and noexec
|
||||
if [[ -d /var/lib/toolbox ]]; then
|
||||
INSTALL_DIR="/var/lib/toolbox/kops"
|
||||
fi
|
||||
mkdir -p ${INSTALL_DIR}/bin
|
||||
mkdir -p ${INSTALL_DIR}/conf
|
||||
cd ${INSTALL_DIR}
|
||||
}
|
||||
|
||||
# Retry a download until we get it. args: name, sha, urls
|
||||
download-or-bust() {
|
||||
local -r file="$1"
|
||||
local -r hash="$2"
|
||||
local -r urls=( $(split-commas "$3") )
|
||||
|
||||
if [[ -f "${file}" ]]; then
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
rm -f "${file}"
|
||||
else
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
while true; do
|
||||
for url in "${urls[@]}"; do
|
||||
commands=(
|
||||
"curl -f --compressed -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget --compression=auto -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
"curl -f -Lo "${file}" --connect-timeout 20 --retry 6 --retry-delay 10"
|
||||
"wget -O "${file}" --connect-timeout=20 --tries=6 --wait=10"
|
||||
)
|
||||
for cmd in "${commands[@]}"; do
|
||||
echo "Attempting download with: ${cmd} {url}"
|
||||
if ! (${cmd} "${url}"); then
|
||||
echo "== Download failed with ${cmd} =="
|
||||
continue
|
||||
fi
|
||||
if ! validate-hash "${file}" "${hash}"; then
|
||||
echo "== Hash validation of ${url} failed. Retrying. =="
|
||||
rm -f "${file}"
|
||||
else
|
||||
echo "== Downloaded ${url} (SHA256 = ${hash}) =="
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "All downloads failed; sleeping before retrying"
|
||||
sleep 60
|
||||
done
|
||||
}
|
||||
|
||||
validate-hash() {
|
||||
local -r file="$1"
|
||||
local -r expected="$2"
|
||||
local actual
|
||||
|
||||
actual=$(sha256sum ${file} | awk '{ print $1 }') || true
|
||||
if [[ "${actual}" != "${expected}" ]]; then
|
||||
echo "== ${file} corrupted, hash ${actual} doesn't match expected ${expected} =="
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
function split-commas() {
|
||||
echo $1 | tr "," "\n"
|
||||
}
|
||||
|
||||
function download-release() {
|
||||
case "$(uname -m)" in
|
||||
x86_64*|i?86_64*|amd64*)
|
||||
NODEUP_URL="${NODEUP_URL_AMD64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_AMD64}"
|
||||
;;
|
||||
aarch64*|arm64*)
|
||||
NODEUP_URL="${NODEUP_URL_ARM64}"
|
||||
NODEUP_HASH="${NODEUP_HASH_ARM64}"
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported host arch: $(uname -m)" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
cd ${INSTALL_DIR}/bin
|
||||
download-or-bust nodeup "${NODEUP_HASH}" "${NODEUP_URL}"
|
||||
|
||||
chmod +x nodeup
|
||||
|
||||
echo "Running nodeup"
|
||||
# We can't run in the foreground because of https://github.com/docker/docker/issues/23793
|
||||
( cd ${INSTALL_DIR}/bin; ./nodeup --install-systemd-unit --conf=${INSTALL_DIR}/conf/kube_env.yaml --v=8 )
|
||||
}
|
||||
|
||||
####################################################################################
|
||||
|
||||
/bin/systemd-machine-id-setup || echo "failed to set up ensure machine-id configured"
|
||||
|
||||
echo "== nodeup node config starting =="
|
||||
ensure-install-dir
|
||||
|
||||
cat > conf/cluster_spec.yaml << '__EOF_CLUSTER_SPEC'
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
docker:
|
||||
skipInstall: true
|
||||
encryptionConfig: null
|
||||
etcdClusters:
|
||||
events:
|
||||
cpuRequest: 100m
|
||||
memoryRequest: 100Mi
|
||||
version: 3.5.4
|
||||
main:
|
||||
cpuRequest: 200m
|
||||
memoryRequest: 100Mi
|
||||
version: 3.5.4
|
||||
kubeAPIServer:
|
||||
allowPrivileged: true
|
||||
anonymousAuth: false
|
||||
apiAudiences:
|
||||
- kubernetes.svc.default
|
||||
apiServerCount: 3
|
||||
authorizationMode: Node,RBAC
|
||||
bindAddress: 0.0.0.0
|
||||
cloudProvider: external
|
||||
enableAdmissionPlugins:
|
||||
- NamespaceLifecycle
|
||||
- LimitRanger
|
||||
- ServiceAccount
|
||||
- DefaultStorageClass
|
||||
- DefaultTolerationSeconds
|
||||
- MutatingAdmissionWebhook
|
||||
- ValidatingAdmissionWebhook
|
||||
- NodeRestriction
|
||||
- ResourceQuota
|
||||
etcdServers:
|
||||
- https://127.0.0.1:4001
|
||||
etcdServersOverrides:
|
||||
- /events#https://127.0.0.1:4002
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-apiserver:v1.25.2@sha256:86e7b79379dddf58d7b7189d02ca96cc7e07d18efa4eb42adcaa4cf94531b96e
|
||||
kubeletPreferredAddressTypes:
|
||||
- InternalIP
|
||||
- Hostname
|
||||
- ExternalIP
|
||||
logLevel: 2
|
||||
requestheaderAllowedNames:
|
||||
- aggregator
|
||||
requestheaderExtraHeaderPrefixes:
|
||||
- X-Remote-Extra-
|
||||
requestheaderGroupHeaders:
|
||||
- X-Remote-Group
|
||||
requestheaderUsernameHeaders:
|
||||
- X-Remote-User
|
||||
securePort: 443
|
||||
serviceAccountIssuer: https://api.internal.dev.datasaker.io
|
||||
serviceAccountJWKSURI: https://api.internal.dev.datasaker.io/openid/v1/jwks
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
storageBackend: etcd3
|
||||
kubeControllerManager:
|
||||
allocateNodeCIDRs: true
|
||||
attachDetachReconcileSyncPeriod: 1m0s
|
||||
cloudProvider: external
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
clusterName: dev.datasaker.io
|
||||
configureCloudRoutes: false
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-controller-manager:v1.25.2@sha256:f961aee35fd2e9a5ee057365e56c5bf40a39bfef91f785f312e51891db41876b
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
useServiceAccountCredentials: true
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubeScheduler:
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-scheduler:v1.25.2@sha256:ef2e24a920a7432aff5b435562301dde3beb528b0c7bbec58ddf0a9af64d5fce
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
masterKubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
registerSchedulable: false
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
|
||||
__EOF_CLUSTER_SPEC
|
||||
|
||||
cat > conf/kube_env.yaml << '__EOF_KUBE_ENV'
|
||||
CloudProvider: aws
|
||||
ConfigBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
InstanceGroupName: master-ap-northeast-2c
|
||||
InstanceGroupRole: Master
|
||||
NodeupConfigHash: jBEDU8SvgVWo5cG3BGBSUNYwYZZoorJwlehYum+BqPA=
|
||||
|
||||
__EOF_KUBE_ENV
|
||||
|
||||
download-release
|
||||
echo "== nodeup node config done =="
|
||||
@@ -0,0 +1,275 @@
|
||||
apiVersion: kops.k8s.io/v1alpha2
|
||||
kind: Cluster
|
||||
metadata:
|
||||
creationTimestamp: "2022-09-13T04:27:37Z"
|
||||
generation: 2
|
||||
name: dev.datasaker.io
|
||||
spec:
|
||||
api:
|
||||
loadBalancer:
|
||||
class: Classic
|
||||
type: Public
|
||||
authorization:
|
||||
rbac: {}
|
||||
channel: stable
|
||||
cloudConfig:
|
||||
awsEBSCSIDriver:
|
||||
enabled: true
|
||||
version: v1.8.0
|
||||
manageStorageClasses: true
|
||||
cloudControllerManager:
|
||||
allocateNodeCIDRs: true
|
||||
clusterCIDR: 100.64.0.0/10
|
||||
clusterName: dev.datasaker.io
|
||||
configureCloudRoutes: false
|
||||
image: registry.k8s.io/provider-aws/cloud-controller-manager:v1.25.0
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
cloudProvider: aws
|
||||
clusterDNSDomain: cluster.local
|
||||
configBase: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
configStore: s3://clusters.dev.datasaker.io/dev.datasaker.io
|
||||
containerRuntime: containerd
|
||||
containerd:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
dnsZone: Z072735718G25WNVKU834
|
||||
docker:
|
||||
skipInstall: true
|
||||
etcdClusters:
|
||||
- backups:
|
||||
backupStore: s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/main
|
||||
cpuRequest: 200m
|
||||
etcdMembers:
|
||||
- encryptedVolume: true
|
||||
instanceGroup: master-ap-northeast-2a
|
||||
name: a
|
||||
- encryptedVolume: true
|
||||
instanceGroup: master-ap-northeast-2b
|
||||
name: b
|
||||
- encryptedVolume: true
|
||||
instanceGroup: master-ap-northeast-2c
|
||||
name: c
|
||||
memoryRequest: 100Mi
|
||||
name: main
|
||||
version: 3.5.4
|
||||
- backups:
|
||||
backupStore: s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/events
|
||||
cpuRequest: 100m
|
||||
etcdMembers:
|
||||
- encryptedVolume: true
|
||||
instanceGroup: master-ap-northeast-2a
|
||||
name: a
|
||||
- encryptedVolume: true
|
||||
instanceGroup: master-ap-northeast-2b
|
||||
name: b
|
||||
- encryptedVolume: true
|
||||
instanceGroup: master-ap-northeast-2c
|
||||
name: c
|
||||
memoryRequest: 100Mi
|
||||
name: events
|
||||
version: 3.5.4
|
||||
externalDns:
|
||||
provider: dns-controller
|
||||
iam:
|
||||
allowContainerRegistry: true
|
||||
legacy: false
|
||||
keyStore: s3://clusters.dev.datasaker.io/dev.datasaker.io/pki
|
||||
kubeAPIServer:
|
||||
allowPrivileged: true
|
||||
anonymousAuth: false
|
||||
apiAudiences:
|
||||
- kubernetes.svc.default
|
||||
apiServerCount: 3
|
||||
authorizationMode: Node,RBAC
|
||||
bindAddress: 0.0.0.0
|
||||
cloudProvider: external
|
||||
enableAdmissionPlugins:
|
||||
- NamespaceLifecycle
|
||||
- LimitRanger
|
||||
- ServiceAccount
|
||||
- DefaultStorageClass
|
||||
- DefaultTolerationSeconds
|
||||
- MutatingAdmissionWebhook
|
||||
- ValidatingAdmissionWebhook
|
||||
- NodeRestriction
|
||||
- ResourceQuota
|
||||
etcdServers:
|
||||
- https://127.0.0.1:4001
|
||||
etcdServersOverrides:
|
||||
- /events#https://127.0.0.1:4002
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-apiserver:v1.25.2@sha256:86e7b79379dddf58d7b7189d02ca96cc7e07d18efa4eb42adcaa4cf94531b96e
|
||||
kubeletPreferredAddressTypes:
|
||||
- InternalIP
|
||||
- Hostname
|
||||
- ExternalIP
|
||||
logLevel: 2
|
||||
requestheaderAllowedNames:
|
||||
- aggregator
|
||||
requestheaderExtraHeaderPrefixes:
|
||||
- X-Remote-Extra-
|
||||
requestheaderGroupHeaders:
|
||||
- X-Remote-Group
|
||||
requestheaderUsernameHeaders:
|
||||
- X-Remote-User
|
||||
securePort: 443
|
||||
serviceAccountIssuer: https://api.internal.dev.datasaker.io
|
||||
serviceAccountJWKSURI: https://api.internal.dev.datasaker.io/openid/v1/jwks
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
storageBackend: etcd3
|
||||
kubeControllerManager:
|
||||
allocateNodeCIDRs: true
|
||||
attachDetachReconcileSyncPeriod: 1m0s
|
||||
cloudProvider: external
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
clusterName: dev.datasaker.io
|
||||
configureCloudRoutes: false
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-controller-manager:v1.25.2@sha256:f961aee35fd2e9a5ee057365e56c5bf40a39bfef91f785f312e51891db41876b
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
useServiceAccountCredentials: true
|
||||
kubeDNS:
|
||||
cacheMaxConcurrent: 150
|
||||
cacheMaxSize: 1000
|
||||
cpuRequest: 100m
|
||||
domain: cluster.local
|
||||
memoryLimit: 170Mi
|
||||
memoryRequest: 70Mi
|
||||
nodeLocalDNS:
|
||||
cpuRequest: 25m
|
||||
enabled: false
|
||||
image: registry.k8s.io/dns/k8s-dns-node-cache:1.22.8
|
||||
memoryRequest: 5Mi
|
||||
provider: CoreDNS
|
||||
serverIP: 100.64.0.10
|
||||
kubeProxy:
|
||||
clusterCIDR: 100.96.0.0/11
|
||||
cpuRequest: 100m
|
||||
image: registry.k8s.io/kube-proxy:v1.25.2@sha256:ddde7d23d168496d321ef9175a8bf964a54a982b026fb207c306d853cbbd4f77
|
||||
logLevel: 2
|
||||
kubeScheduler:
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-scheduler:v1.25.2@sha256:ef2e24a920a7432aff5b435562301dde3beb528b0c7bbec58ddf0a9af64d5fce
|
||||
leaderElection:
|
||||
leaderElect: true
|
||||
logLevel: 2
|
||||
kubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
kubernetesApiAccess:
|
||||
- 0.0.0.0/0
|
||||
- ::/0
|
||||
kubernetesVersion: 1.25.2
|
||||
masterInternalName: api.internal.dev.datasaker.io
|
||||
masterKubelet:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
registerSchedulable: false
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
masterPublicName: api.dev.datasaker.io
|
||||
networkCIDR: 172.21.0.0/16
|
||||
networkID: vpc-0b6e0b906c678a22f
|
||||
networking:
|
||||
calico:
|
||||
encapsulationMode: ipip
|
||||
nonMasqueradeCIDR: 100.64.0.0/10
|
||||
podCIDR: 100.96.0.0/11
|
||||
secretStore: s3://clusters.dev.datasaker.io/dev.datasaker.io/secrets
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
sshAccess:
|
||||
- 0.0.0.0/0
|
||||
- ::/0
|
||||
subnets:
|
||||
- cidr: 172.21.8.0/23
|
||||
id: subnet-0c875e254456809f7
|
||||
name: ap-northeast-2a
|
||||
type: Private
|
||||
zone: ap-northeast-2a
|
||||
- cidr: 172.21.10.0/23
|
||||
id: subnet-05672a669943fc12f
|
||||
name: ap-northeast-2b
|
||||
type: Private
|
||||
zone: ap-northeast-2b
|
||||
- cidr: 172.21.12.0/23
|
||||
id: subnet-0940fd78504acbbde
|
||||
name: ap-northeast-2c
|
||||
type: Private
|
||||
zone: ap-northeast-2c
|
||||
- cidr: 172.21.0.0/24
|
||||
id: subnet-0de55619bee2411f8
|
||||
name: utility-ap-northeast-2a
|
||||
type: Utility
|
||||
zone: ap-northeast-2a
|
||||
- cidr: 172.21.1.0/24
|
||||
id: subnet-0a5d787353f874684
|
||||
name: utility-ap-northeast-2b
|
||||
type: Utility
|
||||
zone: ap-northeast-2b
|
||||
- cidr: 172.21.2.0/24
|
||||
id: subnet-0ee26ffc561efb292
|
||||
name: utility-ap-northeast-2c
|
||||
type: Utility
|
||||
zone: ap-northeast-2c
|
||||
topology:
|
||||
dns:
|
||||
type: Public
|
||||
masters: private
|
||||
nodes: private
|
||||
@@ -0,0 +1,237 @@
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-cloud-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: aws-cloud-controller.addons.k8s.io
|
||||
k8s-app: aws-cloud-controller-manager
|
||||
name: aws-cloud-controller-manager
|
||||
namespace: kube-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: aws-cloud-controller-manager
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: aws-cloud-controller-manager
|
||||
kops.k8s.io/managed-by: kops
|
||||
spec:
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
containers:
|
||||
- args:
|
||||
- --allocate-node-cidrs=true
|
||||
- --cluster-cidr=100.64.0.0/10
|
||||
- --cluster-name=dev.datasaker.io
|
||||
- --configure-cloud-routes=false
|
||||
- --leader-elect=true
|
||||
- --v=2
|
||||
- --cloud-provider=aws
|
||||
- --use-service-account-credentials=true
|
||||
- --cloud-config=/etc/kubernetes/cloud.config
|
||||
env:
|
||||
- name: KUBERNETES_SERVICE_HOST
|
||||
value: 127.0.0.1
|
||||
image: registry.k8s.io/provider-aws/cloud-controller-manager:v1.25.0@sha256:d12285173cb301d08ce1a56256782478ec2ec334f3af345b9f753b8de2598aad
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: aws-cloud-controller-manager
|
||||
resources:
|
||||
requests:
|
||||
cpu: 200m
|
||||
volumeMounts:
|
||||
- mountPath: /etc/kubernetes/cloud.config
|
||||
name: cloudconfig
|
||||
readOnly: true
|
||||
hostNetwork: true
|
||||
nodeSelector: null
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccountName: aws-cloud-controller-manager
|
||||
tolerations:
|
||||
- effect: NoSchedule
|
||||
key: node.cloudprovider.kubernetes.io/uninitialized
|
||||
value: "true"
|
||||
- effect: NoSchedule
|
||||
key: node.kubernetes.io/not-ready
|
||||
- effect: NoSchedule
|
||||
key: node-role.kubernetes.io/control-plane
|
||||
- effect: NoSchedule
|
||||
key: node-role.kubernetes.io/master
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/cloud.config
|
||||
type: ""
|
||||
name: cloudconfig
|
||||
updateStrategy:
|
||||
type: RollingUpdate
|
||||
|
||||
---
|
||||
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-cloud-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: aws-cloud-controller.addons.k8s.io
|
||||
name: aws-cloud-controller-manager
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-cloud-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: aws-cloud-controller.addons.k8s.io
|
||||
name: cloud-controller-manager:apiserver-authentication-reader
|
||||
namespace: kube-system
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: extension-apiserver-authentication-reader
|
||||
subjects:
|
||||
- apiGroup: ""
|
||||
kind: ServiceAccount
|
||||
name: aws-cloud-controller-manager
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-cloud-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: aws-cloud-controller.addons.k8s.io
|
||||
name: system:cloud-controller-manager
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes/status
|
||||
verbs:
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- services
|
||||
verbs:
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- services/status
|
||||
verbs:
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- serviceaccounts
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- endpoints
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- secrets
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resourceNames:
|
||||
- node-controller
|
||||
- service-controller
|
||||
- route-controller
|
||||
resources:
|
||||
- serviceaccounts/token
|
||||
verbs:
|
||||
- create
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-cloud-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: aws-cloud-controller.addons.k8s.io
|
||||
name: system:cloud-controller-manager
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:cloud-controller-manager
|
||||
subjects:
|
||||
- apiGroup: ""
|
||||
kind: ServiceAccount
|
||||
name: aws-cloud-controller-manager
|
||||
namespace: kube-system
|
||||
@@ -0,0 +1,785 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-controller-sa
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-external-attacher-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- csi.storage.k8s.io
|
||||
resources:
|
||||
- csinodeinfos
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- storage.k8s.io
|
||||
resources:
|
||||
- volumeattachments
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- storage.k8s.io
|
||||
resources:
|
||||
- volumeattachments/status
|
||||
verbs:
|
||||
- patch
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-external-provisioner-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumeclaims
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- storage.k8s.io
|
||||
resources:
|
||||
- storageclasses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- snapshot.storage.k8s.io
|
||||
resources:
|
||||
- volumesnapshots
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- snapshot.storage.k8s.io
|
||||
resources:
|
||||
- volumesnapshotcontents
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- storage.k8s.io
|
||||
resources:
|
||||
- csinodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- get
|
||||
- watch
|
||||
- list
|
||||
- delete
|
||||
- update
|
||||
- create
|
||||
- apiGroups:
|
||||
- storage.k8s.io
|
||||
resources:
|
||||
- volumeattachments
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-external-resizer-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumeclaims
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumeclaims/status
|
||||
verbs:
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- storage.k8s.io
|
||||
resources:
|
||||
- storageclasses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-external-snapshotter-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- snapshot.storage.k8s.io
|
||||
resources:
|
||||
- volumesnapshotclasses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- snapshot.storage.k8s.io
|
||||
resources:
|
||||
- volumesnapshotcontents
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- patch
|
||||
- apiGroups:
|
||||
- snapshot.storage.k8s.io
|
||||
resources:
|
||||
- volumesnapshotcontents/status
|
||||
verbs:
|
||||
- update
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-attacher-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: ebs-external-attacher-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: ebs-csi-controller-sa
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-provisioner-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: ebs-external-provisioner-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: ebs-csi-controller-sa
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-resizer-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: ebs-external-resizer-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: ebs-csi-controller-sa
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-snapshotter-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: ebs-external-snapshotter-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: ebs-csi-controller-sa
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-node-getter-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: ebs-csi-node-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: ebs-csi-node-sa
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-node-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
|
||||
---
|
||||
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-node-sa
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-node
|
||||
namespace: kube-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: ebs-csi-node
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
app: ebs-csi-node
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
kops.k8s.io/managed-by: kops
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- node
|
||||
- --endpoint=$(CSI_ENDPOINT)
|
||||
- --logtostderr
|
||||
- --v=2
|
||||
env:
|
||||
- name: CSI_ENDPOINT
|
||||
value: unix:/csi/csi.sock
|
||||
- name: CSI_NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.nodeName
|
||||
image: registry.k8s.io/provider-aws/aws-ebs-csi-driver:v1.8.0@sha256:2727c4ba96b420f6280107daaf4a40a5de5f7241a1b70052056a5016dff05b2f
|
||||
imagePullPolicy: IfNotPresent
|
||||
livenessProbe:
|
||||
failureThreshold: 5
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
name: ebs-plugin
|
||||
ports:
|
||||
- containerPort: 9808
|
||||
name: healthz
|
||||
protocol: TCP
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- mountPath: /var/lib/kubelet
|
||||
mountPropagation: Bidirectional
|
||||
name: kubelet-dir
|
||||
- mountPath: /csi
|
||||
name: plugin-dir
|
||||
- mountPath: /dev
|
||||
name: device-dir
|
||||
- args:
|
||||
- --csi-address=$(ADDRESS)
|
||||
- --kubelet-registration-path=$(DRIVER_REG_SOCK_PATH)
|
||||
- --v=5
|
||||
env:
|
||||
- name: ADDRESS
|
||||
value: /csi/csi.sock
|
||||
- name: DRIVER_REG_SOCK_PATH
|
||||
value: /var/lib/kubelet/plugins/ebs.csi.aws.com/csi.sock
|
||||
image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.1@sha256:0103eee7c35e3e0b5cd8cdca9850dc71c793cdeb6669d8be7a89440da2d06ae4
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: node-driver-registrar
|
||||
volumeMounts:
|
||||
- mountPath: /csi
|
||||
name: plugin-dir
|
||||
- mountPath: /registration
|
||||
name: registration-dir
|
||||
- args:
|
||||
- --csi-address=/csi/csi.sock
|
||||
image: registry.k8s.io/sig-storage/livenessprobe:v2.5.0@sha256:44d8275b3f145bc290fd57cb00de2d713b5e72d2e827d8c5555f8ddb40bf3f02
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: liveness-probe
|
||||
volumeMounts:
|
||||
- mountPath: /csi
|
||||
name: plugin-dir
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
priorityClassName: system-node-critical
|
||||
serviceAccountName: ebs-csi-node-sa
|
||||
tolerations:
|
||||
- operator: Exists
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /var/lib/kubelet
|
||||
type: Directory
|
||||
name: kubelet-dir
|
||||
- hostPath:
|
||||
path: /var/lib/kubelet/plugins/ebs.csi.aws.com/
|
||||
type: DirectoryOrCreate
|
||||
name: plugin-dir
|
||||
- hostPath:
|
||||
path: /var/lib/kubelet/plugins_registry/
|
||||
type: Directory
|
||||
name: registration-dir
|
||||
- hostPath:
|
||||
path: /dev
|
||||
type: Directory
|
||||
name: device-dir
|
||||
|
||||
---
|
||||
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-controller
|
||||
namespace: kube-system
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: ebs-csi-controller
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
app: ebs-csi-controller
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
kops.k8s.io/managed-by: kops
|
||||
spec:
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
containers:
|
||||
- args:
|
||||
- controller
|
||||
- --endpoint=$(CSI_ENDPOINT)
|
||||
- --logtostderr
|
||||
- --k8s-tag-cluster-id=dev.datasaker.io
|
||||
- --extra-tags=KubernetesCluster=dev.datasaker.io
|
||||
- --v=5
|
||||
env:
|
||||
- name: CSI_ENDPOINT
|
||||
value: unix:///var/lib/csi/sockets/pluginproxy/csi.sock
|
||||
- name: CSI_NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
apiVersion: v1
|
||||
fieldPath: spec.nodeName
|
||||
- name: AWS_ACCESS_KEY_ID
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: key_id
|
||||
name: aws-secret
|
||||
optional: true
|
||||
- name: AWS_SECRET_ACCESS_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: access_key
|
||||
name: aws-secret
|
||||
optional: true
|
||||
image: registry.k8s.io/provider-aws/aws-ebs-csi-driver:v1.8.0@sha256:2727c4ba96b420f6280107daaf4a40a5de5f7241a1b70052056a5016dff05b2f
|
||||
imagePullPolicy: IfNotPresent
|
||||
livenessProbe:
|
||||
failureThreshold: 5
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
name: ebs-plugin
|
||||
ports:
|
||||
- containerPort: 9808
|
||||
name: healthz
|
||||
protocol: TCP
|
||||
readinessProbe:
|
||||
failureThreshold: 5
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
volumeMounts:
|
||||
- mountPath: /var/lib/csi/sockets/pluginproxy/
|
||||
name: socket-dir
|
||||
- args:
|
||||
- --csi-address=$(ADDRESS)
|
||||
- --v=5
|
||||
- --feature-gates=Topology=true
|
||||
- --extra-create-metadata
|
||||
- --leader-election=true
|
||||
- --default-fstype=ext4
|
||||
env:
|
||||
- name: ADDRESS
|
||||
value: /var/lib/csi/sockets/pluginproxy/csi.sock
|
||||
image: registry.k8s.io/sig-storage/csi-provisioner:v3.1.0@sha256:122bfb8c1edabb3c0edd63f06523e6940d958d19b3957dc7b1d6f81e9f1f6119
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: csi-provisioner
|
||||
volumeMounts:
|
||||
- mountPath: /var/lib/csi/sockets/pluginproxy/
|
||||
name: socket-dir
|
||||
- args:
|
||||
- --csi-address=$(ADDRESS)
|
||||
- --v=5
|
||||
- --leader-election=true
|
||||
env:
|
||||
- name: ADDRESS
|
||||
value: /var/lib/csi/sockets/pluginproxy/csi.sock
|
||||
image: registry.k8s.io/sig-storage/csi-attacher:v3.4.0@sha256:8b9c313c05f54fb04f8d430896f5f5904b6cb157df261501b29adc04d2b2dc7b
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: csi-attacher
|
||||
volumeMounts:
|
||||
- mountPath: /var/lib/csi/sockets/pluginproxy/
|
||||
name: socket-dir
|
||||
- args:
|
||||
- --csi-address=$(ADDRESS)
|
||||
- --v=5
|
||||
env:
|
||||
- name: ADDRESS
|
||||
value: /var/lib/csi/sockets/pluginproxy/csi.sock
|
||||
image: registry.k8s.io/sig-storage/csi-resizer:v1.4.0@sha256:9ebbf9f023e7b41ccee3d52afe39a89e3ddacdbb69269d583abfc25847cfd9e4
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: csi-resizer
|
||||
volumeMounts:
|
||||
- mountPath: /var/lib/csi/sockets/pluginproxy/
|
||||
name: socket-dir
|
||||
- args:
|
||||
- --csi-address=/csi/csi.sock
|
||||
image: registry.k8s.io/sig-storage/livenessprobe:v2.5.0@sha256:44d8275b3f145bc290fd57cb00de2d713b5e72d2e827d8c5555f8ddb40bf3f02
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: liveness-probe
|
||||
volumeMounts:
|
||||
- mountPath: /csi
|
||||
name: socket-dir
|
||||
nodeSelector: null
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccountName: ebs-csi-controller-sa
|
||||
tolerations:
|
||||
- operator: Exists
|
||||
topologySpreadConstraints:
|
||||
- labelSelector:
|
||||
matchLabels:
|
||||
app: ebs-csi-controller
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
maxSkew: 1
|
||||
topologyKey: topology.kubernetes.io/zone
|
||||
whenUnsatisfiable: ScheduleAnyway
|
||||
- labelSelector:
|
||||
matchLabels:
|
||||
app: ebs-csi-controller
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
maxSkew: 1
|
||||
topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: DoNotSchedule
|
||||
volumes:
|
||||
- emptyDir: {}
|
||||
name: socket-dir
|
||||
|
||||
---
|
||||
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: CSIDriver
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs.csi.aws.com
|
||||
spec:
|
||||
attachRequired: true
|
||||
podInfoOnMount: false
|
||||
|
||||
---
|
||||
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: aws-ebs-csi-driver.addons.k8s.io
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
app.kubernetes.io/managed-by: kops
|
||||
app.kubernetes.io/name: aws-ebs-csi-driver
|
||||
app.kubernetes.io/version: v1.8.0
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
name: ebs-csi-controller
|
||||
namespace: kube-system
|
||||
spec:
|
||||
maxUnavailable: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: ebs-csi-controller
|
||||
app.kubernetes.io/instance: aws-ebs-csi-driver
|
||||
@@ -0,0 +1,118 @@
|
||||
kind: Addons
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: bootstrap
|
||||
spec:
|
||||
addons:
|
||||
- id: k8s-1.16
|
||||
manifest: kops-controller.addons.k8s.io/k8s-1.16.yaml
|
||||
manifestHash: c42ef9711dcd1f31f50a3ee10190ab78be7fd8e896a5c0eef4974ead759db649
|
||||
name: kops-controller.addons.k8s.io
|
||||
needsRollingUpdate: control-plane
|
||||
selector:
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- id: k8s-1.12
|
||||
manifest: coredns.addons.k8s.io/k8s-1.12.yaml
|
||||
manifestHash: e74407f12bb4589901fc6e1785395747588ba2e8788ffbca664d88c4c8da58e5
|
||||
name: coredns.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- id: k8s-1.9
|
||||
manifest: kubelet-api.rbac.addons.k8s.io/k8s-1.9.yaml
|
||||
manifestHash: 01c120e887bd98d82ef57983ad58a0b22bc85efb48108092a24c4b82e4c9ea81
|
||||
name: kubelet-api.rbac.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: kubelet-api.rbac.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- id: k8s-1.23
|
||||
manifest: leader-migration.rbac.addons.k8s.io/k8s-1.23.yaml
|
||||
manifestHash: b9c91e09c0f28c9b74ff140b8395d611834c627d698846d625c10975a74a48c4
|
||||
name: leader-migration.rbac.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: leader-migration.rbac.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- manifest: limit-range.addons.k8s.io/v1.5.0.yaml
|
||||
manifestHash: 2d55c3bc5e354e84a3730a65b42f39aba630a59dc8d32b30859fcce3d3178bc2
|
||||
name: limit-range.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: limit-range.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- id: k8s-1.12
|
||||
manifest: dns-controller.addons.k8s.io/k8s-1.12.yaml
|
||||
manifestHash: 17a7d2855452f5f93b465ea1bcaaa20ad8e94e6e4e544ae17eae7808454fc78d
|
||||
name: dns-controller.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: dns-controller.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- id: v1.15.0
|
||||
manifest: storage-aws.addons.k8s.io/v1.15.0.yaml
|
||||
manifestHash: 4e2cda50cd5048133aad1b5e28becb60f4629d3f9e09c514a2757c27998b4200
|
||||
name: storage-aws.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: storage-aws.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- id: k8s-1.25
|
||||
manifest: networking.projectcalico.org/k8s-1.25.yaml
|
||||
manifestHash: a3d712db23f74a4313682e8ff77b2bd1fa58568526507291f8cbfa694efe6995
|
||||
name: networking.projectcalico.org
|
||||
prune:
|
||||
kinds:
|
||||
- kind: ConfigMap
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
namespaces:
|
||||
- kube-system
|
||||
- kind: Service
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
- kind: ServiceAccount
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
namespaces:
|
||||
- kube-system
|
||||
- group: apps
|
||||
kind: DaemonSet
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
namespaces:
|
||||
- kube-system
|
||||
- group: apps
|
||||
kind: Deployment
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
namespaces:
|
||||
- kube-system
|
||||
- group: apps
|
||||
kind: StatefulSet
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
- group: policy
|
||||
kind: PodDisruptionBudget
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
namespaces:
|
||||
- kube-system
|
||||
- group: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
- group: rbac.authorization.k8s.io
|
||||
kind: ClusterRoleBinding
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
- group: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
- group: rbac.authorization.k8s.io
|
||||
kind: RoleBinding
|
||||
labelSelector: addon.kops.k8s.io/name=networking.projectcalico.org,app.kubernetes.io/managed-by=kops
|
||||
selector:
|
||||
role.kubernetes.io/networking: "1"
|
||||
version: 9.99.0
|
||||
- id: k8s-1.18
|
||||
manifest: aws-cloud-controller.addons.k8s.io/k8s-1.18.yaml
|
||||
manifestHash: 7f65474ed049a1a20b3360ff214f97ebeb660160a06f329cc0cff62f4c7d0fdf
|
||||
name: aws-cloud-controller.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: aws-cloud-controller.addons.k8s.io
|
||||
version: 9.99.0
|
||||
- id: k8s-1.17
|
||||
manifest: aws-ebs-csi-driver.addons.k8s.io/k8s-1.17.yaml
|
||||
manifestHash: 8b9b712bbb505db50b8c92325440ea039f26f18b6e82c171827ecafaba2f2c2f
|
||||
name: aws-ebs-csi-driver.addons.k8s.io
|
||||
selector:
|
||||
k8s-addon: aws-ebs-csi-driver.addons.k8s.io
|
||||
version: 9.99.0
|
||||
@@ -0,0 +1,383 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
kubernetes.io/cluster-service: "true"
|
||||
name: coredns
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
kubernetes.io/bootstrapping: rbac-defaults
|
||||
name: system:coredns
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- endpoints
|
||||
- services
|
||||
- pods
|
||||
- namespaces
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- discovery.k8s.io
|
||||
resources:
|
||||
- endpointslices
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
annotations:
|
||||
rbac.authorization.kubernetes.io/autoupdate: "true"
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
kubernetes.io/bootstrapping: rbac-defaults
|
||||
name: system:coredns
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:coredns
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: coredns
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: v1
|
||||
data:
|
||||
Corefile: |-
|
||||
.:53 {
|
||||
errors
|
||||
health {
|
||||
lameduck 5s
|
||||
}
|
||||
ready
|
||||
kubernetes cluster.local. in-addr.arpa ip6.arpa {
|
||||
pods insecure
|
||||
fallthrough in-addr.arpa ip6.arpa
|
||||
ttl 30
|
||||
}
|
||||
prometheus :9153
|
||||
forward . /etc/resolv.conf {
|
||||
max_concurrent 1000
|
||||
}
|
||||
cache 30
|
||||
loop
|
||||
reload
|
||||
loadbalance
|
||||
}
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
addonmanager.kubernetes.io/mode: EnsureExists
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
name: coredns
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
k8s-app: kube-dns
|
||||
kubernetes.io/cluster-service: "true"
|
||||
kubernetes.io/name: CoreDNS
|
||||
name: coredns
|
||||
namespace: kube-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: kube-dns
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxSurge: 10%
|
||||
maxUnavailable: 1
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: kube-dns
|
||||
kops.k8s.io/managed-by: kops
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- -conf
|
||||
- /etc/coredns/Corefile
|
||||
image: registry.k8s.io/coredns/coredns:v1.9.3@sha256:8e352a029d304ca7431c6507b56800636c321cb52289686a581ab70aaa8a2e2a
|
||||
imagePullPolicy: IfNotPresent
|
||||
livenessProbe:
|
||||
failureThreshold: 5
|
||||
httpGet:
|
||||
path: /health
|
||||
port: 8080
|
||||
scheme: HTTP
|
||||
initialDelaySeconds: 60
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 5
|
||||
name: coredns
|
||||
ports:
|
||||
- containerPort: 53
|
||||
name: dns
|
||||
protocol: UDP
|
||||
- containerPort: 53
|
||||
name: dns-tcp
|
||||
protocol: TCP
|
||||
- containerPort: 9153
|
||||
name: metrics
|
||||
protocol: TCP
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /ready
|
||||
port: 8181
|
||||
scheme: HTTP
|
||||
resources:
|
||||
limits:
|
||||
memory: 170Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 70Mi
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
add:
|
||||
- NET_BIND_SERVICE
|
||||
drop:
|
||||
- all
|
||||
readOnlyRootFilesystem: true
|
||||
volumeMounts:
|
||||
- mountPath: /etc/coredns
|
||||
name: config-volume
|
||||
readOnly: true
|
||||
dnsPolicy: Default
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccountName: coredns
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
topologySpreadConstraints:
|
||||
- labelSelector:
|
||||
matchLabels:
|
||||
k8s-app: kube-dns
|
||||
maxSkew: 1
|
||||
topologyKey: topology.kubernetes.io/zone
|
||||
whenUnsatisfiable: ScheduleAnyway
|
||||
- labelSelector:
|
||||
matchLabels:
|
||||
k8s-app: kube-dns
|
||||
maxSkew: 1
|
||||
topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: ScheduleAnyway
|
||||
volumes:
|
||||
- configMap:
|
||||
name: coredns
|
||||
name: config-volume
|
||||
|
||||
---
|
||||
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
annotations:
|
||||
prometheus.io/port: "9153"
|
||||
prometheus.io/scrape: "true"
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
k8s-app: kube-dns
|
||||
kubernetes.io/cluster-service: "true"
|
||||
kubernetes.io/name: CoreDNS
|
||||
name: kube-dns
|
||||
namespace: kube-system
|
||||
resourceVersion: "0"
|
||||
spec:
|
||||
clusterIP: 100.64.0.10
|
||||
ports:
|
||||
- name: dns
|
||||
port: 53
|
||||
protocol: UDP
|
||||
- name: dns-tcp
|
||||
port: 53
|
||||
protocol: TCP
|
||||
- name: metrics
|
||||
port: 9153
|
||||
protocol: TCP
|
||||
selector:
|
||||
k8s-app: kube-dns
|
||||
|
||||
---
|
||||
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
name: kube-dns
|
||||
namespace: kube-system
|
||||
spec:
|
||||
maxUnavailable: 50%
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: kube-dns
|
||||
|
||||
---
|
||||
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
name: coredns-autoscaler
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
name: coredns-autoscaler
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- replicationcontrollers/scale
|
||||
verbs:
|
||||
- get
|
||||
- update
|
||||
- apiGroups:
|
||||
- extensions
|
||||
- apps
|
||||
resources:
|
||||
- deployments/scale
|
||||
- replicasets/scale
|
||||
verbs:
|
||||
- get
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
name: coredns-autoscaler
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: coredns-autoscaler
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: coredns-autoscaler
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: coredns.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: coredns.addons.k8s.io
|
||||
k8s-app: coredns-autoscaler
|
||||
kubernetes.io/cluster-service: "true"
|
||||
name: coredns-autoscaler
|
||||
namespace: kube-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: coredns-autoscaler
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: coredns-autoscaler
|
||||
kops.k8s.io/managed-by: kops
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- /cluster-proportional-autoscaler
|
||||
- --namespace=kube-system
|
||||
- --configmap=coredns-autoscaler
|
||||
- --target=Deployment/coredns
|
||||
- --default-params={"linear":{"coresPerReplica":256,"nodesPerReplica":16,"preventSinglePointFailure":true}}
|
||||
- --logtostderr=true
|
||||
- --v=2
|
||||
image: registry.k8s.io/cpa/cluster-proportional-autoscaler:1.8.5@sha256:aa60f453d64dfb3c3fd9e7306f988c36c6352c4f2d956aa90467f2808091effa
|
||||
name: autoscaler
|
||||
resources:
|
||||
requests:
|
||||
cpu: 20m
|
||||
memory: 10Mi
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccountName: coredns-autoscaler
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
@@ -0,0 +1,138 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: dns-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: dns-controller.addons.k8s.io
|
||||
k8s-app: dns-controller
|
||||
version: v1.25.0
|
||||
name: dns-controller
|
||||
namespace: kube-system
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: dns-controller
|
||||
strategy:
|
||||
type: Recreate
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-addon: dns-controller.addons.k8s.io
|
||||
k8s-app: dns-controller
|
||||
kops.k8s.io/managed-by: kops
|
||||
version: v1.25.0
|
||||
spec:
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
containers:
|
||||
- args:
|
||||
- --watch-ingress=false
|
||||
- --dns=aws-route53
|
||||
- --zone=*/Z072735718G25WNVKU834
|
||||
- --internal-ipv4
|
||||
- --zone=*/*
|
||||
- -v=2
|
||||
command: null
|
||||
env:
|
||||
- name: KUBERNETES_SERVICE_HOST
|
||||
value: 127.0.0.1
|
||||
image: registry.k8s.io/kops/dns-controller:1.25.0@sha256:635bf83f6dc4f6d7ee42b90c005c5ec61d9fbdd56c25eff3150e4ce5e0c77699
|
||||
name: dns-controller
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 50Mi
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
dnsPolicy: Default
|
||||
hostNetwork: true
|
||||
nodeSelector: null
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccount: dns-controller
|
||||
tolerations:
|
||||
- key: node.cloudprovider.kubernetes.io/uninitialized
|
||||
operator: Exists
|
||||
- key: node.kubernetes.io/not-ready
|
||||
operator: Exists
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
|
||||
---
|
||||
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: dns-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: dns-controller.addons.k8s.io
|
||||
name: dns-controller
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: dns-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: dns-controller.addons.k8s.io
|
||||
name: kops:dns-controller
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- endpoints
|
||||
- services
|
||||
- pods
|
||||
- ingress
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- networking.k8s.io
|
||||
resources:
|
||||
- ingresses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: dns-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: dns-controller.addons.k8s.io
|
||||
name: kops:dns-controller
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: kops:dns-controller
|
||||
subjects:
|
||||
- apiGroup: rbac.authorization.k8s.io
|
||||
kind: User
|
||||
name: system:serviceaccount:kube-system:dns-controller
|
||||
@@ -0,0 +1,225 @@
|
||||
apiVersion: v1
|
||||
data:
|
||||
config.yaml: |
|
||||
{"cloud":"aws","configBase":"s3://clusters.dev.datasaker.io/dev.datasaker.io","server":{"Listen":":3988","provider":{"aws":{"nodesRoles":["nodes.dev.datasaker.io"],"Region":"ap-northeast-2"}},"serverKeyPath":"/etc/kubernetes/kops-controller/pki/kops-controller.key","serverCertificatePath":"/etc/kubernetes/kops-controller/pki/kops-controller.crt","caBasePath":"/etc/kubernetes/kops-controller/pki","signingCAs":["kubernetes-ca"],"certNames":["kubelet","kubelet-server","kube-proxy"],"useInstanceIDForNodeName":true}}
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kops-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
name: kops-controller
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kops-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
k8s-app: kops-controller
|
||||
version: v1.25.0
|
||||
name: kops-controller
|
||||
namespace: kube-system
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
k8s-app: kops-controller
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
dns.alpha.kubernetes.io/internal: kops-controller.internal.dev.datasaker.io
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
k8s-app: kops-controller
|
||||
kops.k8s.io/managed-by: kops
|
||||
version: v1.25.0
|
||||
spec:
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
- key: kops.k8s.io/kops-controller-pki
|
||||
operator: Exists
|
||||
- matchExpressions:
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
- key: kops.k8s.io/kops-controller-pki
|
||||
operator: Exists
|
||||
containers:
|
||||
- args:
|
||||
- --v=2
|
||||
- --conf=/etc/kubernetes/kops-controller/config/config.yaml
|
||||
command: null
|
||||
env:
|
||||
- name: KUBERNETES_SERVICE_HOST
|
||||
value: 127.0.0.1
|
||||
image: registry.k8s.io/kops/kops-controller:1.25.0@sha256:ffca50fd02426835e9b3c51d950e0726774de27934d944457a0391d8ba64a5e6
|
||||
name: kops-controller
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 50Mi
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 10011
|
||||
volumeMounts:
|
||||
- mountPath: /etc/kubernetes/kops-controller/config/
|
||||
name: kops-controller-config
|
||||
- mountPath: /etc/kubernetes/kops-controller/pki/
|
||||
name: kops-controller-pki
|
||||
dnsPolicy: Default
|
||||
hostNetwork: true
|
||||
nodeSelector: null
|
||||
priorityClassName: system-cluster-critical
|
||||
serviceAccount: kops-controller
|
||||
tolerations:
|
||||
- key: node.cloudprovider.kubernetes.io/uninitialized
|
||||
operator: Exists
|
||||
- key: node.kubernetes.io/not-ready
|
||||
operator: Exists
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
volumes:
|
||||
- configMap:
|
||||
name: kops-controller
|
||||
name: kops-controller-config
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/kops-controller/
|
||||
type: Directory
|
||||
name: kops-controller-pki
|
||||
updateStrategy:
|
||||
type: OnDelete
|
||||
|
||||
---
|
||||
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kops-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
name: kops-controller
|
||||
namespace: kube-system
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kops-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
name: kops-controller
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- patch
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kops-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
name: kops-controller
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: kops-controller
|
||||
subjects:
|
||||
- apiGroup: rbac.authorization.k8s.io
|
||||
kind: User
|
||||
name: system:serviceaccount:kube-system:kops-controller
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kops-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
name: kops-controller
|
||||
namespace: kube-system
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- apiGroups:
|
||||
- ""
|
||||
- coordination.k8s.io
|
||||
resourceNames:
|
||||
- kops-controller-leader
|
||||
resources:
|
||||
- configmaps
|
||||
- leases
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- patch
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- configmaps
|
||||
- leases
|
||||
verbs:
|
||||
- create
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kops-controller.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kops-controller.addons.k8s.io
|
||||
name: kops-controller
|
||||
namespace: kube-system
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: kops-controller
|
||||
subjects:
|
||||
- apiGroup: rbac.authorization.k8s.io
|
||||
kind: User
|
||||
name: system:serviceaccount:kube-system:kops-controller
|
||||
@@ -0,0 +1,17 @@
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: kubelet-api.rbac.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: kubelet-api.rbac.addons.k8s.io
|
||||
name: kops:system:kubelet-api-admin
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:kubelet-api-admin
|
||||
subjects:
|
||||
- apiGroup: rbac.authorization.k8s.io
|
||||
kind: User
|
||||
name: kubelet-api
|
||||
@@ -0,0 +1,52 @@
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: leader-migration.rbac.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: leader-migration.rbac.addons.k8s.io
|
||||
name: system::leader-locking-migration
|
||||
namespace: kube-system
|
||||
rules:
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resourceNames:
|
||||
- cloud-provider-extraction-migration
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- create
|
||||
- list
|
||||
- get
|
||||
- update
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: leader-migration.rbac.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: leader-migration.rbac.addons.k8s.io
|
||||
name: system::leader-locking-migration
|
||||
namespace: kube-system
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: system::leader-locking-migration
|
||||
subjects:
|
||||
- apiGroup: rbac.authorization.k8s.io
|
||||
kind: User
|
||||
name: system:kube-controller-manager
|
||||
- kind: ServiceAccount
|
||||
name: kube-controller-manager
|
||||
namespace: kube-system
|
||||
- kind: ServiceAccount
|
||||
name: aws-cloud-controller-manager
|
||||
namespace: kube-system
|
||||
- kind: ServiceAccount
|
||||
name: cloud-controller-manager
|
||||
namespace: kube-system
|
||||
@@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: LimitRange
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: limit-range.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: limit-range.addons.k8s.io
|
||||
name: limits
|
||||
namespace: default
|
||||
spec:
|
||||
limits:
|
||||
- defaultRequest:
|
||||
cpu: 100m
|
||||
type: Container
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,118 @@
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: storage-aws.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: storage-aws.addons.k8s.io
|
||||
name: default
|
||||
parameters:
|
||||
type: gp2
|
||||
provisioner: kubernetes.io/aws-ebs
|
||||
|
||||
---
|
||||
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
annotations:
|
||||
storageclass.kubernetes.io/is-default-class: "false"
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: storage-aws.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: storage-aws.addons.k8s.io
|
||||
name: gp2
|
||||
parameters:
|
||||
type: gp2
|
||||
provisioner: kubernetes.io/aws-ebs
|
||||
|
||||
---
|
||||
|
||||
allowVolumeExpansion: true
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
annotations:
|
||||
storageclass.kubernetes.io/is-default-class: "false"
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: storage-aws.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: storage-aws.addons.k8s.io
|
||||
name: kops-ssd-1-17
|
||||
parameters:
|
||||
encrypted: "true"
|
||||
type: gp2
|
||||
provisioner: kubernetes.io/aws-ebs
|
||||
volumeBindingMode: WaitForFirstConsumer
|
||||
|
||||
---
|
||||
|
||||
allowVolumeExpansion: true
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
annotations:
|
||||
storageclass.kubernetes.io/is-default-class: "true"
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: storage-aws.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: storage-aws.addons.k8s.io
|
||||
name: kops-csi-1-21
|
||||
parameters:
|
||||
encrypted: "true"
|
||||
type: gp3
|
||||
provisioner: ebs.csi.aws.com
|
||||
volumeBindingMode: WaitForFirstConsumer
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: storage-aws.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: storage-aws.addons.k8s.io
|
||||
name: system:aws-cloud-provider
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
|
||||
---
|
||||
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
addon.kops.k8s.io/name: storage-aws.addons.k8s.io
|
||||
app.kubernetes.io/managed-by: kops
|
||||
k8s-addon: storage-aws.addons.k8s.io
|
||||
name: system:aws-cloud-provider
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: system:aws-cloud-provider
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: aws-cloud-provider
|
||||
namespace: kube-system
|
||||
@@ -0,0 +1,4 @@
|
||||
{
|
||||
"memberCount": 3,
|
||||
"etcdVersion": "3.5.4"
|
||||
}
|
||||
@@ -0,0 +1,4 @@
|
||||
{
|
||||
"memberCount": 3,
|
||||
"etcdVersion": "3.5.4"
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
1.25.0
|
||||
@@ -0,0 +1,61 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: etcd-manager-events
|
||||
name: etcd-manager-events
|
||||
namespace: kube-system
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /etcd-manager
|
||||
--backup-store=s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/events
|
||||
--client-urls=https://__name__:4002 --cluster-name=etcd-events --containerized=true
|
||||
--dns-suffix=.internal.dev.datasaker.io --grpc-port=3997 --peer-urls=https://__name__:2381
|
||||
--quarantine-client-urls=https://__name__:3995 --v=6 --volume-name-tag=k8s.io/etcd/events
|
||||
--volume-provider=aws --volume-tag=k8s.io/etcd/events --volume-tag=k8s.io/role/master=1
|
||||
--volume-tag=kubernetes.io/cluster/dev.datasaker.io=owned > /tmp/pipe 2>&1
|
||||
image: registry.k8s.io/etcdadm/etcd-manager:v3.0.20220831@sha256:a91fdaf9b988943a9c73d422348c2383c08dfc2566d4124a39a1b3d785018720
|
||||
name: etcd-manager
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 100Mi
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- mountPath: /rootfs
|
||||
name: rootfs
|
||||
- mountPath: /run
|
||||
name: run
|
||||
- mountPath: /etc/kubernetes/pki/etcd-manager
|
||||
name: pki
|
||||
- mountPath: /var/log/etcd.log
|
||||
name: varlogetcd
|
||||
hostNetwork: true
|
||||
hostPID: true
|
||||
priorityClassName: system-cluster-critical
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
name: rootfs
|
||||
- hostPath:
|
||||
path: /run
|
||||
type: DirectoryOrCreate
|
||||
name: run
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/pki/etcd-manager-events
|
||||
type: DirectoryOrCreate
|
||||
name: pki
|
||||
- hostPath:
|
||||
path: /var/log/etcd-events.log
|
||||
type: FileOrCreate
|
||||
name: varlogetcd
|
||||
status: {}
|
||||
@@ -0,0 +1,61 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: etcd-manager-events
|
||||
name: etcd-manager-events
|
||||
namespace: kube-system
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /etcd-manager
|
||||
--backup-store=s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/events
|
||||
--client-urls=https://__name__:4002 --cluster-name=etcd-events --containerized=true
|
||||
--dns-suffix=.internal.dev.datasaker.io --grpc-port=3997 --peer-urls=https://__name__:2381
|
||||
--quarantine-client-urls=https://__name__:3995 --v=6 --volume-name-tag=k8s.io/etcd/events
|
||||
--volume-provider=aws --volume-tag=k8s.io/etcd/events --volume-tag=k8s.io/role/master=1
|
||||
--volume-tag=kubernetes.io/cluster/dev.datasaker.io=owned > /tmp/pipe 2>&1
|
||||
image: registry.k8s.io/etcdadm/etcd-manager:v3.0.20220831@sha256:a91fdaf9b988943a9c73d422348c2383c08dfc2566d4124a39a1b3d785018720
|
||||
name: etcd-manager
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 100Mi
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- mountPath: /rootfs
|
||||
name: rootfs
|
||||
- mountPath: /run
|
||||
name: run
|
||||
- mountPath: /etc/kubernetes/pki/etcd-manager
|
||||
name: pki
|
||||
- mountPath: /var/log/etcd.log
|
||||
name: varlogetcd
|
||||
hostNetwork: true
|
||||
hostPID: true
|
||||
priorityClassName: system-cluster-critical
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
name: rootfs
|
||||
- hostPath:
|
||||
path: /run
|
||||
type: DirectoryOrCreate
|
||||
name: run
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/pki/etcd-manager-events
|
||||
type: DirectoryOrCreate
|
||||
name: pki
|
||||
- hostPath:
|
||||
path: /var/log/etcd-events.log
|
||||
type: FileOrCreate
|
||||
name: varlogetcd
|
||||
status: {}
|
||||
@@ -0,0 +1,61 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: etcd-manager-events
|
||||
name: etcd-manager-events
|
||||
namespace: kube-system
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /etcd-manager
|
||||
--backup-store=s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/events
|
||||
--client-urls=https://__name__:4002 --cluster-name=etcd-events --containerized=true
|
||||
--dns-suffix=.internal.dev.datasaker.io --grpc-port=3997 --peer-urls=https://__name__:2381
|
||||
--quarantine-client-urls=https://__name__:3995 --v=6 --volume-name-tag=k8s.io/etcd/events
|
||||
--volume-provider=aws --volume-tag=k8s.io/etcd/events --volume-tag=k8s.io/role/master=1
|
||||
--volume-tag=kubernetes.io/cluster/dev.datasaker.io=owned > /tmp/pipe 2>&1
|
||||
image: registry.k8s.io/etcdadm/etcd-manager:v3.0.20220831@sha256:a91fdaf9b988943a9c73d422348c2383c08dfc2566d4124a39a1b3d785018720
|
||||
name: etcd-manager
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 100Mi
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- mountPath: /rootfs
|
||||
name: rootfs
|
||||
- mountPath: /run
|
||||
name: run
|
||||
- mountPath: /etc/kubernetes/pki/etcd-manager
|
||||
name: pki
|
||||
- mountPath: /var/log/etcd.log
|
||||
name: varlogetcd
|
||||
hostNetwork: true
|
||||
hostPID: true
|
||||
priorityClassName: system-cluster-critical
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
name: rootfs
|
||||
- hostPath:
|
||||
path: /run
|
||||
type: DirectoryOrCreate
|
||||
name: run
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/pki/etcd-manager-events
|
||||
type: DirectoryOrCreate
|
||||
name: pki
|
||||
- hostPath:
|
||||
path: /var/log/etcd-events.log
|
||||
type: FileOrCreate
|
||||
name: varlogetcd
|
||||
status: {}
|
||||
@@ -0,0 +1,61 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: etcd-manager-main
|
||||
name: etcd-manager-main
|
||||
namespace: kube-system
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /etcd-manager
|
||||
--backup-store=s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/main
|
||||
--client-urls=https://__name__:4001 --cluster-name=etcd --containerized=true
|
||||
--dns-suffix=.internal.dev.datasaker.io --grpc-port=3996 --peer-urls=https://__name__:2380
|
||||
--quarantine-client-urls=https://__name__:3994 --v=6 --volume-name-tag=k8s.io/etcd/main
|
||||
--volume-provider=aws --volume-tag=k8s.io/etcd/main --volume-tag=k8s.io/role/master=1
|
||||
--volume-tag=kubernetes.io/cluster/dev.datasaker.io=owned > /tmp/pipe 2>&1
|
||||
image: registry.k8s.io/etcdadm/etcd-manager:v3.0.20220831@sha256:a91fdaf9b988943a9c73d422348c2383c08dfc2566d4124a39a1b3d785018720
|
||||
name: etcd-manager
|
||||
resources:
|
||||
requests:
|
||||
cpu: 200m
|
||||
memory: 100Mi
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- mountPath: /rootfs
|
||||
name: rootfs
|
||||
- mountPath: /run
|
||||
name: run
|
||||
- mountPath: /etc/kubernetes/pki/etcd-manager
|
||||
name: pki
|
||||
- mountPath: /var/log/etcd.log
|
||||
name: varlogetcd
|
||||
hostNetwork: true
|
||||
hostPID: true
|
||||
priorityClassName: system-cluster-critical
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
name: rootfs
|
||||
- hostPath:
|
||||
path: /run
|
||||
type: DirectoryOrCreate
|
||||
name: run
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/pki/etcd-manager-main
|
||||
type: DirectoryOrCreate
|
||||
name: pki
|
||||
- hostPath:
|
||||
path: /var/log/etcd.log
|
||||
type: FileOrCreate
|
||||
name: varlogetcd
|
||||
status: {}
|
||||
@@ -0,0 +1,61 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: etcd-manager-main
|
||||
name: etcd-manager-main
|
||||
namespace: kube-system
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /etcd-manager
|
||||
--backup-store=s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/main
|
||||
--client-urls=https://__name__:4001 --cluster-name=etcd --containerized=true
|
||||
--dns-suffix=.internal.dev.datasaker.io --grpc-port=3996 --peer-urls=https://__name__:2380
|
||||
--quarantine-client-urls=https://__name__:3994 --v=6 --volume-name-tag=k8s.io/etcd/main
|
||||
--volume-provider=aws --volume-tag=k8s.io/etcd/main --volume-tag=k8s.io/role/master=1
|
||||
--volume-tag=kubernetes.io/cluster/dev.datasaker.io=owned > /tmp/pipe 2>&1
|
||||
image: registry.k8s.io/etcdadm/etcd-manager:v3.0.20220831@sha256:a91fdaf9b988943a9c73d422348c2383c08dfc2566d4124a39a1b3d785018720
|
||||
name: etcd-manager
|
||||
resources:
|
||||
requests:
|
||||
cpu: 200m
|
||||
memory: 100Mi
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- mountPath: /rootfs
|
||||
name: rootfs
|
||||
- mountPath: /run
|
||||
name: run
|
||||
- mountPath: /etc/kubernetes/pki/etcd-manager
|
||||
name: pki
|
||||
- mountPath: /var/log/etcd.log
|
||||
name: varlogetcd
|
||||
hostNetwork: true
|
||||
hostPID: true
|
||||
priorityClassName: system-cluster-critical
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
name: rootfs
|
||||
- hostPath:
|
||||
path: /run
|
||||
type: DirectoryOrCreate
|
||||
name: run
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/pki/etcd-manager-main
|
||||
type: DirectoryOrCreate
|
||||
name: pki
|
||||
- hostPath:
|
||||
path: /var/log/etcd.log
|
||||
type: FileOrCreate
|
||||
name: varlogetcd
|
||||
status: {}
|
||||
@@ -0,0 +1,61 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
k8s-app: etcd-manager-main
|
||||
name: etcd-manager-main
|
||||
namespace: kube-system
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /etcd-manager
|
||||
--backup-store=s3://clusters.dev.datasaker.io/dev.datasaker.io/backups/etcd/main
|
||||
--client-urls=https://__name__:4001 --cluster-name=etcd --containerized=true
|
||||
--dns-suffix=.internal.dev.datasaker.io --grpc-port=3996 --peer-urls=https://__name__:2380
|
||||
--quarantine-client-urls=https://__name__:3994 --v=6 --volume-name-tag=k8s.io/etcd/main
|
||||
--volume-provider=aws --volume-tag=k8s.io/etcd/main --volume-tag=k8s.io/role/master=1
|
||||
--volume-tag=kubernetes.io/cluster/dev.datasaker.io=owned > /tmp/pipe 2>&1
|
||||
image: registry.k8s.io/etcdadm/etcd-manager:v3.0.20220831@sha256:a91fdaf9b988943a9c73d422348c2383c08dfc2566d4124a39a1b3d785018720
|
||||
name: etcd-manager
|
||||
resources:
|
||||
requests:
|
||||
cpu: 200m
|
||||
memory: 100Mi
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- mountPath: /rootfs
|
||||
name: rootfs
|
||||
- mountPath: /run
|
||||
name: run
|
||||
- mountPath: /etc/kubernetes/pki/etcd-manager
|
||||
name: pki
|
||||
- mountPath: /var/log/etcd.log
|
||||
name: varlogetcd
|
||||
hostNetwork: true
|
||||
hostPID: true
|
||||
priorityClassName: system-cluster-critical
|
||||
tolerations:
|
||||
- key: CriticalAddonsOnly
|
||||
operator: Exists
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
name: rootfs
|
||||
- hostPath:
|
||||
path: /run
|
||||
type: DirectoryOrCreate
|
||||
name: run
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/pki/etcd-manager-main
|
||||
type: DirectoryOrCreate
|
||||
name: pki
|
||||
- hostPath:
|
||||
path: /var/log/etcd.log
|
||||
type: FileOrCreate
|
||||
name: varlogetcd
|
||||
status: {}
|
||||
@@ -0,0 +1,33 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- --ca-cert=/secrets/ca.crt
|
||||
- --client-cert=/secrets/client.crt
|
||||
- --client-key=/secrets/client.key
|
||||
image: registry.k8s.io/kops/kube-apiserver-healthcheck:1.25.0@sha256:3a9fc2225bedd410645becec263d8e25c0f978406d46c54837422db978b8505a
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
host: 127.0.0.1
|
||||
path: /.kube-apiserver-healthcheck/healthz
|
||||
port: 3990
|
||||
initialDelaySeconds: 5
|
||||
timeoutSeconds: 5
|
||||
name: healthcheck
|
||||
resources: {}
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 10012
|
||||
volumeMounts:
|
||||
- mountPath: /secrets
|
||||
name: healthcheck-secrets
|
||||
readOnly: true
|
||||
volumes:
|
||||
- hostPath:
|
||||
path: /etc/kubernetes/kube-apiserver-healthcheck/secrets
|
||||
type: Directory
|
||||
name: healthcheck-secrets
|
||||
status: {}
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: data-druid
|
||||
kops.k8s.io/instancegroup: dev-data-druid-a
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/data-druid:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: data-druid
|
||||
kops.k8s.io/instancegroup: dev-data-druid-b
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/data-druid:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: data-druid
|
||||
kops.k8s.io/instancegroup: dev-data-druid-c
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/data-druid:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: data-kafka
|
||||
kops.k8s.io/instancegroup: dev-data-kafka-a
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/data-kafka:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: data-kafka
|
||||
kops.k8s.io/instancegroup: dev-data-kafka-b
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/data-kafka:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: data-kafka
|
||||
kops.k8s.io/instancegroup: dev-data-kafka-c
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/data-kafka:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: mgmt
|
||||
kops.k8s.io/instancegroup: dev-mgmt-a
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/mgmt:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: mgmt
|
||||
kops.k8s.io/instancegroup: dev-mgmt-b
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/mgmt:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,89 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: mgmt
|
||||
kops.k8s.io/instancegroup: dev-mgmt-c
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
taints:
|
||||
- dev/mgmt:NoSchedule
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,87 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: process
|
||||
kops.k8s.io/instancegroup: dev-process-a
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,87 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: process
|
||||
kops.k8s.io/instancegroup: dev-process-b
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,87 @@
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
CAs:
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
datasaker/group: process
|
||||
kops.k8s.io/instancegroup: dev-process-c
|
||||
node-role.kubernetes.io/node: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,288 @@
|
||||
APIServerConfig:
|
||||
KubeAPIServer:
|
||||
allowPrivileged: true
|
||||
anonymousAuth: false
|
||||
apiAudiences:
|
||||
- kubernetes.svc.default
|
||||
apiServerCount: 3
|
||||
authorizationMode: Node,RBAC
|
||||
bindAddress: 0.0.0.0
|
||||
cloudProvider: external
|
||||
enableAdmissionPlugins:
|
||||
- NamespaceLifecycle
|
||||
- LimitRanger
|
||||
- ServiceAccount
|
||||
- DefaultStorageClass
|
||||
- DefaultTolerationSeconds
|
||||
- MutatingAdmissionWebhook
|
||||
- ValidatingAdmissionWebhook
|
||||
- NodeRestriction
|
||||
- ResourceQuota
|
||||
etcdServers:
|
||||
- https://127.0.0.1:4001
|
||||
etcdServersOverrides:
|
||||
- /events#https://127.0.0.1:4002
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-apiserver:v1.25.2@sha256:86e7b79379dddf58d7b7189d02ca96cc7e07d18efa4eb42adcaa4cf94531b96e
|
||||
kubeletPreferredAddressTypes:
|
||||
- InternalIP
|
||||
- Hostname
|
||||
- ExternalIP
|
||||
logLevel: 2
|
||||
requestheaderAllowedNames:
|
||||
- aggregator
|
||||
requestheaderExtraHeaderPrefixes:
|
||||
- X-Remote-Extra-
|
||||
requestheaderGroupHeaders:
|
||||
- X-Remote-Group
|
||||
requestheaderUsernameHeaders:
|
||||
- X-Remote-User
|
||||
securePort: 443
|
||||
serviceAccountIssuer: https://api.internal.dev.datasaker.io
|
||||
serviceAccountJWKSURI: https://api.internal.dev.datasaker.io/openid/v1/jwks
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
storageBackend: etcd3
|
||||
ServiceAccountPublicKeys: |
|
||||
-----BEGIN RSA PUBLIC KEY-----
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4UK3R2fjYWGtlIJU3nBS
|
||||
UTIX9Eg+vp9Uw4zMhkz1K5BnyB2IsKR0F9LnMdLaTrF7Zo1Bef82Ew80eKS0JwY5
|
||||
NOj+ZP9FiC7bVRRdeuW5KMGjEmhWSz/mVahxgo0pRE9xP3yA2Ij1lQjn3R0Yr6ec
|
||||
E+fwjAF2o93L+KpBzcXrpGiPa0+Qx1I8VPKLyLjM/SfK3eBUcouNbWeGi8+DULAf
|
||||
DHMUA7B6U+w/IbEd3kVCTSWEBK+R2CAl8sIMZ424wGnNX58G4yy2uGYlcOItTZzU
|
||||
fPt9ulI1DYvycFTkPzedFu+KF5GlulcqMqmPRANWDSj26gDmahVoraO0eQ9vCDhp
|
||||
vwIDAQAB
|
||||
-----END RSA PUBLIC KEY-----
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
- 8f01da0b6bf77d36b28840186c5387ecda831036d0d671805b6a5367bdd1b284@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/protokube,https://github.com/kubernetes/kops/releases/download/v1.25.0/protokube-linux-amd64
|
||||
- 7ba778d62bbca3ec158c62279713ef774f695f341e264ea572a0b7cbdd022071@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/channels,https://github.com/kubernetes/kops/releases/download/v1.25.0/channels-linux-amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
- dead6a79da3a04785c25b03fef625b3d220bf77e2b0750b525023c48a70f4081@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/protokube,https://github.com/kubernetes/kops/releases/download/v1.25.0/protokube-linux-arm64
|
||||
- 609d23833768046d3626eba1c8dd620ce86d7235bbe3073f4c6241f26c31e456@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/channels,https://github.com/kubernetes/kops/releases/download/v1.25.0/channels-linux-arm64
|
||||
CAs:
|
||||
apiserver-aggregator-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDDDCCAfSgAwIBAgIMFxRSNNb6vi6f8FSFMA0GCSqGSIb3DQEBCwUAMCIxIDAe
|
||||
BgNVBAMTF2FwaXNlcnZlci1hZ2dyZWdhdG9yLWNhMB4XDTIyMDkxMTA0NDkwOVoX
|
||||
DTMyMDkxMDA0NDkwOVowIjEgMB4GA1UEAxMXYXBpc2VydmVyLWFnZ3JlZ2F0b3It
|
||||
Y2EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC2CwCYipJHeykxywc/
|
||||
wcAZQzTt49XYDHsTnMPtdSkF4Qdy+cwRi1SpL5cpO9ByqGwZ7exXKhe6EAOhfmmG
|
||||
yZgDvI95434tp6a64mbBmCrR+4NIKDIkoXIrhEGogbJlDij/K63yVCAZCPulyj7G
|
||||
VyE7X4bEmvuAbYDeJheX+ZFGhV5iLS2fri13NMEp9a9nms22V9hJitLxzV3LLdl5
|
||||
db/q3LMb96xl27ccbcSyz5gEuKJfvKqEb7bCVg6yJbdbVO+CMLpnIMFsiXwwSyO0
|
||||
xXrCzyeNHAB9eK/n0gGkWb/RKoLqXTUNdGu4SvaPYnTJKAT2eHvBNAlPt5rJO5Kt
|
||||
Yz4xAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0G
|
||||
A1UdDgQWBBT1GhQw65WfbiDWTeUx5k1xHMz/ajANBgkqhkiG9w0BAQsFAAOCAQEA
|
||||
Uih4ajNq0Yys9IFBziOT+W2rxdodQOzcJpXWTdSNnxRzOtasjiYUoGdzdizT54Y4
|
||||
wjtWnBGgB+sre3pTF8TNnv/AlBLx8t0ANOifcncPLRFsBtJVDFCuglPXrn5cHDOr
|
||||
anLTIzQ3etoDV/h2AQxQafYUg9ZtwgyEbou7kwLi+p9TBJdV3iWowfdgs9HtHagd
|
||||
wL0/v6RU8pojl7hBYIloGB1AIREDSfprxDMzUBDyOY7uyvcfK+RcUoLRuq6Tq2ob
|
||||
PsOtl3ZaSTOmdQ0r8SEUMtOm0jozbyRu9ojq7/+UOu3yT1YeM4M7N6lYNtZx153O
|
||||
ILB6F+I/dTp9EdI/qBNrqg==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-clients-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC/DCCAeSgAwIBAgIMFxRSNNaYe6a0fhC7MA0GCSqGSIb3DQEBCwUAMBoxGDAW
|
||||
BgNVBAMTD2V0Y2QtY2xpZW50cy1jYTAeFw0yMjA5MTEwNDQ5MDlaFw0zMjA5MTAw
|
||||
NDQ5MDlaMBoxGDAWBgNVBAMTD2V0Y2QtY2xpZW50cy1jYTCCASIwDQYJKoZIhvcN
|
||||
AQEBBQADggEPADCCAQoCggEBAJdTYAp2rgiShljdkdR/P1kt81okDYl1q+/6rUS4
|
||||
L8AwJDtbIIvQcmgRgoR3mlhRBQIibeHSWHNlt99TYzkUeQF8n2cE3MJbSNmykGqf
|
||||
A8CxluTyL32TDnsRbonQoDK5wKbWpCFD1KD7P/aozOdsoDlPV18Y46dZ4j3Yv2C1
|
||||
ppaUmv0hQ62eLeDXQlq1e7VFmwiij/lsW/bNXI6r/ENFRbCsfhCCY5xkoOeWPrFJ
|
||||
ci68UbzQssmR0xlcGbCtcxfwmsPi0C9Php5mtpmRWa9uTGbSK3ZD1jx98S2OWWVe
|
||||
1jiCmIyzsqY31QioOveWaCL14JqArO2FqrugXx2ZxAI1OSkCAwEAAaNCMEAwDgYD
|
||||
VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFA4wbacZ59AB
|
||||
n3dc7WLWkb9TF+CUMA0GCSqGSIb3DQEBCwUAA4IBAQBQn+1DUIZOkgTwUmW3Nnt8
|
||||
sWUV7NRy3ZdB9lEbWWwodNRheYMEHUe8y/Z2VvWiYNKA9K0lVYpu0MGF6HiClqhN
|
||||
FWU7eFv6uVGf2ypBNTy5cz+PNYAfxl9U4gBGJRKzuKOICFHp7laKzBuiwk934Daa
|
||||
xeZeA+7Pt23o52APhXVXTKf3U5v/97e631rOfnE+o9D6mL3XnWj5vZ4/1moQD1nm
|
||||
eyRJXT1LaKULk52o52c4O6FIgniit746qyakIllhUk5vMsnlXTjO2v16iyi2i62z
|
||||
jhx8pJzZ2phPBcSjDR+Bm4WbAKvZjAUFQ6MjgqXxxTDtGy52erAzXmjLeqBsHrvi
|
||||
-----END CERTIFICATE-----
|
||||
etcd-manager-ca-events: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDCjCCAfKgAwIBAgIMFxRSNNcAFGGHjduQMA0GCSqGSIb3DQEBCwUAMCExHzAd
|
||||
BgNVBAMTFmV0Y2QtbWFuYWdlci1jYS1ldmVudHMwHhcNMjIwOTExMDQ0OTA5WhcN
|
||||
MzIwOTEwMDQ0OTA5WjAhMR8wHQYDVQQDExZldGNkLW1hbmFnZXItY2EtZXZlbnRz
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3KRK8906XyxKwYZcISZO
|
||||
uEYgQ2WGAZNQXgvxbb5GBAM4f9Pv0JuoAL0uy9qpyqQDq6ACe5jICyvg3+9LU+pW
|
||||
GDxubYHb6f15BJtw36zO6Mgs5BTjrW9zxjJSzZIoGDL7zw+d7B7bASAfuIWZfmmm
|
||||
lMQg/pnywbG1jPTB1rEVOryOHMXntXe6C/CpxTZz66AYYd6+7GrCLC8uHG5PyEie
|
||||
tv7avgRb06RKJQSJ3reGRHJ8UI9bJduTlaQyZpCmfxpqnK7E57SFSuzbcYi/iMGY
|
||||
GUZCfR8tLtsMjDYTxsTCvBQWuVP3FJXS1KKoyfgfQ4AvNhzo/I5K9ZGGb24CvtzZ
|
||||
+QIDAQABo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
|
||||
HQ4EFgQU0pBv8lYo6UyaXEX7P7KPMEIll1kwDQYJKoZIhvcNAQELBQADggEBAG7C
|
||||
vDSF0dAEyThlrhzpUBZX6dLWwRtsGqXmsqS7TTvSExiDxl+27llAVVb6DIg5b3Lp
|
||||
fa4P5cDcflFaNsWz/vCwkB9yoiUm2tCqxRkr1LKY9FIV/FUGwE5imr7HyGmpcbKh
|
||||
xCC+57ZHXuZj7oZsBoTyCVjj+PX6UmqsTMG6GEOuvDvrzqKI1h3WSMtovRjLUmCX
|
||||
cPrwOJJoKzy1gWCNsILSwFmSyklsjIzVFliXp+Si0IHwHwqmVn9JEnz64A5C5nkB
|
||||
jBOFXTznDiPWOmNc2RYumSpNl0srm5fqR9FA21H4DOJI4VmpK8YWwSmwNmmwAZoS
|
||||
XOkBupErXPmZkj/8CEk=
|
||||
-----END CERTIFICATE-----
|
||||
etcd-manager-ca-main: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDBjCCAe6gAwIBAgIMFxRSNNc6k2RDt+raMA0GCSqGSIb3DQEBCwUAMB8xHTAb
|
||||
BgNVBAMTFGV0Y2QtbWFuYWdlci1jYS1tYWluMB4XDTIyMDkxMTA0NDkwOVoXDTMy
|
||||
MDkxMDA0NDkwOVowHzEdMBsGA1UEAxMUZXRjZC1tYW5hZ2VyLWNhLW1haW4wggEi
|
||||
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChc/xsdUXOfkMw/TiONzQ5ymzO
|
||||
4i7seuBYgbBriR1n0PyCFoAmNXMvVt+JtytvBzr0FfPnpjpO+xb+L1MY2m7Rbx4F
|
||||
5brrJN1LwFlZOQjKCpgxOUT+EFVneXvmZx7E0UbJ+TxEGGOZ1N6t1mxdmsdjO0TV
|
||||
mhMg6Nawj1+HAQsdgkMDAWv3PEgUeJCrRg+7KzBQxY0pOVuZkeQZ+MHsR3GLdIZn
|
||||
l3h13ePS6Z1K+Uz4VMR4myV1wXFyOR1Qms7ROZ3wIiCoE/Vqg9bn70funi4PMG0l
|
||||
/Bxj9t2ogMOla7ypNzcwjNRtzhdmuAaEvdrvZ6XF4NXWM8DpjiR9dA3Y0dffAgMB
|
||||
AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
|
||||
BBTD5SaTxIzni41qVldUtl9SqcBM7TANBgkqhkiG9w0BAQsFAAOCAQEANyBp0bU4
|
||||
gJrgLLnjKC/atTvHRzCrLmHz9ECa9bN9I6dAsiyJmxGPPlD+PkhFNxzenQ80VizD
|
||||
qo+w9RQGDtfMD5WX0A8M4KN5A8efTBhWReI9lzxGaRxUwQRiKXBRgn778nFZ7E/5
|
||||
9DmDlibhdb1XEz0X+l6XkNyJdHHsCPi2omKRY6R9W7+/ezvkH6mqAcTC7DufWB77
|
||||
T3sr6lmFR69isQB0kQlhXG/Ws+g6zN7CyRP741sQAPWYfRaziLYSTcdnFHMBNRHc
|
||||
zm3DVnbPCrjV7zjSdoNbPgPvEvZYGMSnK0tfxhYKTVRT8cKWlBBwnPYMKW/O0ED0
|
||||
Z2RjK1J0AFawFQ==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-peers-ca-events: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDBjCCAe6gAwIBAgIMFxRSNNgftEHrucqUMA0GCSqGSIb3DQEBCwUAMB8xHTAb
|
||||
BgNVBAMTFGV0Y2QtcGVlcnMtY2EtZXZlbnRzMB4XDTIyMDkxMTA0NDkwOVoXDTMy
|
||||
MDkxMDA0NDkwOVowHzEdMBsGA1UEAxMUZXRjZC1wZWVycy1jYS1ldmVudHMwggEi
|
||||
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDAA6jobVkkVeddp9oTaVMbthfB
|
||||
dforGm4J/E3KBBmA5+3HXknFZ+nXAK0naZUS2RrHUrigTcux1no1Om3eTJCcxmOR
|
||||
IIFYAjX3vpMXhOMCgh98U/BrN96xdaRPRNF5lwluc26ZLRcS7Y+HeZwORCB0auX4
|
||||
5XZFb72CT2kfWaqnsum7YC/r/aJzUS1dIrGZwKBYCZct3TfCZTzW4aL6rkHdrriJ
|
||||
KNIaV1FR/n6X2hdTpVnHou/mk5Zr0WYz1YaAlJIqHJEavrYIjLp6pWgsho8ESB+D
|
||||
WHEm+cHNVFMuVm++5OWr5PZNLawD44MUomH/DlTVK0B9qdS3gQ6X4Hx6gDS3AgMB
|
||||
AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
|
||||
BBRozlb1pjT7aWt9Kg70JkqBH6y4BzANBgkqhkiG9w0BAQsFAAOCAQEApP3tYKOy
|
||||
hy2AGVeTOfh5YSKuSQQJjyy5mBuHIpB0vYcukSABn+60n7Ku4hAGERucscBjHpWy
|
||||
55BBRDjVvY1jlB4AJKRmlAlGngmwhz9KO86EvxXzJaDfxd92rDY1iOF3DM9UNUCI
|
||||
vlvVA1ws7XhWLlUPZf+Ndpj7s1ar46htDy0ONchhXiokzNcDqNtMgSZzS1+WJY+n
|
||||
n5BjbIO91sQqLsd4DHLVi9ZWcr4LyS9hYSFPSNAPOnNsGnj3WcWTcctH8yUxhzwZ
|
||||
1Cty74gyfTtTENm5dZk+wAjkxTkixO+18NG0PCXos/1FONthR521u3qqLXSZNYL0
|
||||
u1zeRMpGpRYUtA==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-peers-ca-main: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDAjCCAeqgAwIBAgIMFxRSNNb5wROslOvTMA0GCSqGSIb3DQEBCwUAMB0xGzAZ
|
||||
BgNVBAMTEmV0Y2QtcGVlcnMtY2EtbWFpbjAeFw0yMjA5MTEwNDQ5MDlaFw0zMjA5
|
||||
MTAwNDQ5MDlaMB0xGzAZBgNVBAMTEmV0Y2QtcGVlcnMtY2EtbWFpbjCCASIwDQYJ
|
||||
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAMN1BKqeJVUBLg1gS8GIZzld/MG8Xgod
|
||||
F4DQKxYYVI9mmkEpP5nhesYQ8qnnqW6js9URF5GXUoaeiaM/krigc4yYm7YRts7B
|
||||
Lzbd6Mlfo8LaHX5GXE0xHRcW29NmaGq8UbcEmTTxc5EgbBNS/Tfai71HGaO0VmrA
|
||||
P6SbNMrgSAlfap1caLQ8CcUASDqEf+BcjZhgetddqSL2KLkL5ot7IxOS2blzQH/I
|
||||
Jk/2Boi36yQ5JoLPbs/TRAV4wHMci3B9ZNHQrdcqP2zl0zC64eNt5fNgo+F/iH/z
|
||||
2M32O+V3HpOJDvFtSC+Q9Ux3kOC4/dmembZex8IPAGJ4IfCyL3cwJYUCAwEAAaNC
|
||||
MEAwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFMpi
|
||||
L3tJgzuP+QDY3uyx99aMAB0sMA0GCSqGSIb3DQEBCwUAA4IBAQCO1OS0DYntM4ut
|
||||
ZNZIkJA+SAFKy06IAev3o9wBiOzlIM5rVm4TDa0L7qFH/Z2l9bRmWDqDeba281qZ
|
||||
EIFGJI1QPAWX47RbQXJOTOIiGsNoUw4swt6it+NoemARwZAoGPYOXqXLVknXalR5
|
||||
ye33OaoI0EowrHw01sv72mbEqeWhb9XKw3h1UkbfdkZIG9KiftYVAlPUNUSaSy8n
|
||||
ApKbqEw2CcRjSPjeLeS9zbLSj+M20NYlwU56xaxIm64TRk65Ac17PN5KJiOHYuDp
|
||||
1fnHqnbPbOOMdfhuRU1D48sSZlAKFiR3p0vLkSNwfmJmWRTfWuAUNAA339CRTKOb
|
||||
Ge9OTWOZ
|
||||
-----END CERTIFICATE-----
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
FileAssets:
|
||||
- content: |
|
||||
apiVersion: kubescheduler.config.k8s.io/v1beta2
|
||||
clientConnection:
|
||||
kubeconfig: /var/lib/kube-scheduler/kubeconfig
|
||||
kind: KubeSchedulerConfiguration
|
||||
path: /var/lib/kube-scheduler/config.yaml
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
apiserver-aggregator-ca: "7142721951056419283723637893"
|
||||
etcd-clients-ca: "7142721951028761584467841211"
|
||||
etcd-manager-ca-events: "7142721951057921435241405328"
|
||||
etcd-manager-ca-main: "7142721951074386633614158554"
|
||||
etcd-peers-ca-events: "7142721951138880539659455124"
|
||||
etcd-peers-ca-main: "7142721951056140991529806803"
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
service-account: "7142721951191621691964241737"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
kops.k8s.io/instancegroup: master-ap-northeast-2a
|
||||
kops.k8s.io/kops-controller-pki: ""
|
||||
node-role.kubernetes.io/control-plane: ""
|
||||
node.kubernetes.io/exclude-from-external-load-balancers: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
registerSchedulable: false
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
etcdManifests:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/manifests/etcd/main-master-ap-northeast-2a.yaml
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/manifests/etcd/events-master-ap-northeast-2a.yaml
|
||||
staticManifests:
|
||||
- key: kube-apiserver-healthcheck
|
||||
path: manifests/static/kube-apiserver-healthcheck.yaml
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,288 @@
|
||||
APIServerConfig:
|
||||
KubeAPIServer:
|
||||
allowPrivileged: true
|
||||
anonymousAuth: false
|
||||
apiAudiences:
|
||||
- kubernetes.svc.default
|
||||
apiServerCount: 3
|
||||
authorizationMode: Node,RBAC
|
||||
bindAddress: 0.0.0.0
|
||||
cloudProvider: external
|
||||
enableAdmissionPlugins:
|
||||
- NamespaceLifecycle
|
||||
- LimitRanger
|
||||
- ServiceAccount
|
||||
- DefaultStorageClass
|
||||
- DefaultTolerationSeconds
|
||||
- MutatingAdmissionWebhook
|
||||
- ValidatingAdmissionWebhook
|
||||
- NodeRestriction
|
||||
- ResourceQuota
|
||||
etcdServers:
|
||||
- https://127.0.0.1:4001
|
||||
etcdServersOverrides:
|
||||
- /events#https://127.0.0.1:4002
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-apiserver:v1.25.2@sha256:86e7b79379dddf58d7b7189d02ca96cc7e07d18efa4eb42adcaa4cf94531b96e
|
||||
kubeletPreferredAddressTypes:
|
||||
- InternalIP
|
||||
- Hostname
|
||||
- ExternalIP
|
||||
logLevel: 2
|
||||
requestheaderAllowedNames:
|
||||
- aggregator
|
||||
requestheaderExtraHeaderPrefixes:
|
||||
- X-Remote-Extra-
|
||||
requestheaderGroupHeaders:
|
||||
- X-Remote-Group
|
||||
requestheaderUsernameHeaders:
|
||||
- X-Remote-User
|
||||
securePort: 443
|
||||
serviceAccountIssuer: https://api.internal.dev.datasaker.io
|
||||
serviceAccountJWKSURI: https://api.internal.dev.datasaker.io/openid/v1/jwks
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
storageBackend: etcd3
|
||||
ServiceAccountPublicKeys: |
|
||||
-----BEGIN RSA PUBLIC KEY-----
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4UK3R2fjYWGtlIJU3nBS
|
||||
UTIX9Eg+vp9Uw4zMhkz1K5BnyB2IsKR0F9LnMdLaTrF7Zo1Bef82Ew80eKS0JwY5
|
||||
NOj+ZP9FiC7bVRRdeuW5KMGjEmhWSz/mVahxgo0pRE9xP3yA2Ij1lQjn3R0Yr6ec
|
||||
E+fwjAF2o93L+KpBzcXrpGiPa0+Qx1I8VPKLyLjM/SfK3eBUcouNbWeGi8+DULAf
|
||||
DHMUA7B6U+w/IbEd3kVCTSWEBK+R2CAl8sIMZ424wGnNX58G4yy2uGYlcOItTZzU
|
||||
fPt9ulI1DYvycFTkPzedFu+KF5GlulcqMqmPRANWDSj26gDmahVoraO0eQ9vCDhp
|
||||
vwIDAQAB
|
||||
-----END RSA PUBLIC KEY-----
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
- 8f01da0b6bf77d36b28840186c5387ecda831036d0d671805b6a5367bdd1b284@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/protokube,https://github.com/kubernetes/kops/releases/download/v1.25.0/protokube-linux-amd64
|
||||
- 7ba778d62bbca3ec158c62279713ef774f695f341e264ea572a0b7cbdd022071@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/channels,https://github.com/kubernetes/kops/releases/download/v1.25.0/channels-linux-amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
- dead6a79da3a04785c25b03fef625b3d220bf77e2b0750b525023c48a70f4081@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/protokube,https://github.com/kubernetes/kops/releases/download/v1.25.0/protokube-linux-arm64
|
||||
- 609d23833768046d3626eba1c8dd620ce86d7235bbe3073f4c6241f26c31e456@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/channels,https://github.com/kubernetes/kops/releases/download/v1.25.0/channels-linux-arm64
|
||||
CAs:
|
||||
apiserver-aggregator-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDDDCCAfSgAwIBAgIMFxRSNNb6vi6f8FSFMA0GCSqGSIb3DQEBCwUAMCIxIDAe
|
||||
BgNVBAMTF2FwaXNlcnZlci1hZ2dyZWdhdG9yLWNhMB4XDTIyMDkxMTA0NDkwOVoX
|
||||
DTMyMDkxMDA0NDkwOVowIjEgMB4GA1UEAxMXYXBpc2VydmVyLWFnZ3JlZ2F0b3It
|
||||
Y2EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC2CwCYipJHeykxywc/
|
||||
wcAZQzTt49XYDHsTnMPtdSkF4Qdy+cwRi1SpL5cpO9ByqGwZ7exXKhe6EAOhfmmG
|
||||
yZgDvI95434tp6a64mbBmCrR+4NIKDIkoXIrhEGogbJlDij/K63yVCAZCPulyj7G
|
||||
VyE7X4bEmvuAbYDeJheX+ZFGhV5iLS2fri13NMEp9a9nms22V9hJitLxzV3LLdl5
|
||||
db/q3LMb96xl27ccbcSyz5gEuKJfvKqEb7bCVg6yJbdbVO+CMLpnIMFsiXwwSyO0
|
||||
xXrCzyeNHAB9eK/n0gGkWb/RKoLqXTUNdGu4SvaPYnTJKAT2eHvBNAlPt5rJO5Kt
|
||||
Yz4xAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0G
|
||||
A1UdDgQWBBT1GhQw65WfbiDWTeUx5k1xHMz/ajANBgkqhkiG9w0BAQsFAAOCAQEA
|
||||
Uih4ajNq0Yys9IFBziOT+W2rxdodQOzcJpXWTdSNnxRzOtasjiYUoGdzdizT54Y4
|
||||
wjtWnBGgB+sre3pTF8TNnv/AlBLx8t0ANOifcncPLRFsBtJVDFCuglPXrn5cHDOr
|
||||
anLTIzQ3etoDV/h2AQxQafYUg9ZtwgyEbou7kwLi+p9TBJdV3iWowfdgs9HtHagd
|
||||
wL0/v6RU8pojl7hBYIloGB1AIREDSfprxDMzUBDyOY7uyvcfK+RcUoLRuq6Tq2ob
|
||||
PsOtl3ZaSTOmdQ0r8SEUMtOm0jozbyRu9ojq7/+UOu3yT1YeM4M7N6lYNtZx153O
|
||||
ILB6F+I/dTp9EdI/qBNrqg==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-clients-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC/DCCAeSgAwIBAgIMFxRSNNaYe6a0fhC7MA0GCSqGSIb3DQEBCwUAMBoxGDAW
|
||||
BgNVBAMTD2V0Y2QtY2xpZW50cy1jYTAeFw0yMjA5MTEwNDQ5MDlaFw0zMjA5MTAw
|
||||
NDQ5MDlaMBoxGDAWBgNVBAMTD2V0Y2QtY2xpZW50cy1jYTCCASIwDQYJKoZIhvcN
|
||||
AQEBBQADggEPADCCAQoCggEBAJdTYAp2rgiShljdkdR/P1kt81okDYl1q+/6rUS4
|
||||
L8AwJDtbIIvQcmgRgoR3mlhRBQIibeHSWHNlt99TYzkUeQF8n2cE3MJbSNmykGqf
|
||||
A8CxluTyL32TDnsRbonQoDK5wKbWpCFD1KD7P/aozOdsoDlPV18Y46dZ4j3Yv2C1
|
||||
ppaUmv0hQ62eLeDXQlq1e7VFmwiij/lsW/bNXI6r/ENFRbCsfhCCY5xkoOeWPrFJ
|
||||
ci68UbzQssmR0xlcGbCtcxfwmsPi0C9Php5mtpmRWa9uTGbSK3ZD1jx98S2OWWVe
|
||||
1jiCmIyzsqY31QioOveWaCL14JqArO2FqrugXx2ZxAI1OSkCAwEAAaNCMEAwDgYD
|
||||
VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFA4wbacZ59AB
|
||||
n3dc7WLWkb9TF+CUMA0GCSqGSIb3DQEBCwUAA4IBAQBQn+1DUIZOkgTwUmW3Nnt8
|
||||
sWUV7NRy3ZdB9lEbWWwodNRheYMEHUe8y/Z2VvWiYNKA9K0lVYpu0MGF6HiClqhN
|
||||
FWU7eFv6uVGf2ypBNTy5cz+PNYAfxl9U4gBGJRKzuKOICFHp7laKzBuiwk934Daa
|
||||
xeZeA+7Pt23o52APhXVXTKf3U5v/97e631rOfnE+o9D6mL3XnWj5vZ4/1moQD1nm
|
||||
eyRJXT1LaKULk52o52c4O6FIgniit746qyakIllhUk5vMsnlXTjO2v16iyi2i62z
|
||||
jhx8pJzZ2phPBcSjDR+Bm4WbAKvZjAUFQ6MjgqXxxTDtGy52erAzXmjLeqBsHrvi
|
||||
-----END CERTIFICATE-----
|
||||
etcd-manager-ca-events: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDCjCCAfKgAwIBAgIMFxRSNNcAFGGHjduQMA0GCSqGSIb3DQEBCwUAMCExHzAd
|
||||
BgNVBAMTFmV0Y2QtbWFuYWdlci1jYS1ldmVudHMwHhcNMjIwOTExMDQ0OTA5WhcN
|
||||
MzIwOTEwMDQ0OTA5WjAhMR8wHQYDVQQDExZldGNkLW1hbmFnZXItY2EtZXZlbnRz
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3KRK8906XyxKwYZcISZO
|
||||
uEYgQ2WGAZNQXgvxbb5GBAM4f9Pv0JuoAL0uy9qpyqQDq6ACe5jICyvg3+9LU+pW
|
||||
GDxubYHb6f15BJtw36zO6Mgs5BTjrW9zxjJSzZIoGDL7zw+d7B7bASAfuIWZfmmm
|
||||
lMQg/pnywbG1jPTB1rEVOryOHMXntXe6C/CpxTZz66AYYd6+7GrCLC8uHG5PyEie
|
||||
tv7avgRb06RKJQSJ3reGRHJ8UI9bJduTlaQyZpCmfxpqnK7E57SFSuzbcYi/iMGY
|
||||
GUZCfR8tLtsMjDYTxsTCvBQWuVP3FJXS1KKoyfgfQ4AvNhzo/I5K9ZGGb24CvtzZ
|
||||
+QIDAQABo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
|
||||
HQ4EFgQU0pBv8lYo6UyaXEX7P7KPMEIll1kwDQYJKoZIhvcNAQELBQADggEBAG7C
|
||||
vDSF0dAEyThlrhzpUBZX6dLWwRtsGqXmsqS7TTvSExiDxl+27llAVVb6DIg5b3Lp
|
||||
fa4P5cDcflFaNsWz/vCwkB9yoiUm2tCqxRkr1LKY9FIV/FUGwE5imr7HyGmpcbKh
|
||||
xCC+57ZHXuZj7oZsBoTyCVjj+PX6UmqsTMG6GEOuvDvrzqKI1h3WSMtovRjLUmCX
|
||||
cPrwOJJoKzy1gWCNsILSwFmSyklsjIzVFliXp+Si0IHwHwqmVn9JEnz64A5C5nkB
|
||||
jBOFXTznDiPWOmNc2RYumSpNl0srm5fqR9FA21H4DOJI4VmpK8YWwSmwNmmwAZoS
|
||||
XOkBupErXPmZkj/8CEk=
|
||||
-----END CERTIFICATE-----
|
||||
etcd-manager-ca-main: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDBjCCAe6gAwIBAgIMFxRSNNc6k2RDt+raMA0GCSqGSIb3DQEBCwUAMB8xHTAb
|
||||
BgNVBAMTFGV0Y2QtbWFuYWdlci1jYS1tYWluMB4XDTIyMDkxMTA0NDkwOVoXDTMy
|
||||
MDkxMDA0NDkwOVowHzEdMBsGA1UEAxMUZXRjZC1tYW5hZ2VyLWNhLW1haW4wggEi
|
||||
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChc/xsdUXOfkMw/TiONzQ5ymzO
|
||||
4i7seuBYgbBriR1n0PyCFoAmNXMvVt+JtytvBzr0FfPnpjpO+xb+L1MY2m7Rbx4F
|
||||
5brrJN1LwFlZOQjKCpgxOUT+EFVneXvmZx7E0UbJ+TxEGGOZ1N6t1mxdmsdjO0TV
|
||||
mhMg6Nawj1+HAQsdgkMDAWv3PEgUeJCrRg+7KzBQxY0pOVuZkeQZ+MHsR3GLdIZn
|
||||
l3h13ePS6Z1K+Uz4VMR4myV1wXFyOR1Qms7ROZ3wIiCoE/Vqg9bn70funi4PMG0l
|
||||
/Bxj9t2ogMOla7ypNzcwjNRtzhdmuAaEvdrvZ6XF4NXWM8DpjiR9dA3Y0dffAgMB
|
||||
AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
|
||||
BBTD5SaTxIzni41qVldUtl9SqcBM7TANBgkqhkiG9w0BAQsFAAOCAQEANyBp0bU4
|
||||
gJrgLLnjKC/atTvHRzCrLmHz9ECa9bN9I6dAsiyJmxGPPlD+PkhFNxzenQ80VizD
|
||||
qo+w9RQGDtfMD5WX0A8M4KN5A8efTBhWReI9lzxGaRxUwQRiKXBRgn778nFZ7E/5
|
||||
9DmDlibhdb1XEz0X+l6XkNyJdHHsCPi2omKRY6R9W7+/ezvkH6mqAcTC7DufWB77
|
||||
T3sr6lmFR69isQB0kQlhXG/Ws+g6zN7CyRP741sQAPWYfRaziLYSTcdnFHMBNRHc
|
||||
zm3DVnbPCrjV7zjSdoNbPgPvEvZYGMSnK0tfxhYKTVRT8cKWlBBwnPYMKW/O0ED0
|
||||
Z2RjK1J0AFawFQ==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-peers-ca-events: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDBjCCAe6gAwIBAgIMFxRSNNgftEHrucqUMA0GCSqGSIb3DQEBCwUAMB8xHTAb
|
||||
BgNVBAMTFGV0Y2QtcGVlcnMtY2EtZXZlbnRzMB4XDTIyMDkxMTA0NDkwOVoXDTMy
|
||||
MDkxMDA0NDkwOVowHzEdMBsGA1UEAxMUZXRjZC1wZWVycy1jYS1ldmVudHMwggEi
|
||||
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDAA6jobVkkVeddp9oTaVMbthfB
|
||||
dforGm4J/E3KBBmA5+3HXknFZ+nXAK0naZUS2RrHUrigTcux1no1Om3eTJCcxmOR
|
||||
IIFYAjX3vpMXhOMCgh98U/BrN96xdaRPRNF5lwluc26ZLRcS7Y+HeZwORCB0auX4
|
||||
5XZFb72CT2kfWaqnsum7YC/r/aJzUS1dIrGZwKBYCZct3TfCZTzW4aL6rkHdrriJ
|
||||
KNIaV1FR/n6X2hdTpVnHou/mk5Zr0WYz1YaAlJIqHJEavrYIjLp6pWgsho8ESB+D
|
||||
WHEm+cHNVFMuVm++5OWr5PZNLawD44MUomH/DlTVK0B9qdS3gQ6X4Hx6gDS3AgMB
|
||||
AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
|
||||
BBRozlb1pjT7aWt9Kg70JkqBH6y4BzANBgkqhkiG9w0BAQsFAAOCAQEApP3tYKOy
|
||||
hy2AGVeTOfh5YSKuSQQJjyy5mBuHIpB0vYcukSABn+60n7Ku4hAGERucscBjHpWy
|
||||
55BBRDjVvY1jlB4AJKRmlAlGngmwhz9KO86EvxXzJaDfxd92rDY1iOF3DM9UNUCI
|
||||
vlvVA1ws7XhWLlUPZf+Ndpj7s1ar46htDy0ONchhXiokzNcDqNtMgSZzS1+WJY+n
|
||||
n5BjbIO91sQqLsd4DHLVi9ZWcr4LyS9hYSFPSNAPOnNsGnj3WcWTcctH8yUxhzwZ
|
||||
1Cty74gyfTtTENm5dZk+wAjkxTkixO+18NG0PCXos/1FONthR521u3qqLXSZNYL0
|
||||
u1zeRMpGpRYUtA==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-peers-ca-main: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDAjCCAeqgAwIBAgIMFxRSNNb5wROslOvTMA0GCSqGSIb3DQEBCwUAMB0xGzAZ
|
||||
BgNVBAMTEmV0Y2QtcGVlcnMtY2EtbWFpbjAeFw0yMjA5MTEwNDQ5MDlaFw0zMjA5
|
||||
MTAwNDQ5MDlaMB0xGzAZBgNVBAMTEmV0Y2QtcGVlcnMtY2EtbWFpbjCCASIwDQYJ
|
||||
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAMN1BKqeJVUBLg1gS8GIZzld/MG8Xgod
|
||||
F4DQKxYYVI9mmkEpP5nhesYQ8qnnqW6js9URF5GXUoaeiaM/krigc4yYm7YRts7B
|
||||
Lzbd6Mlfo8LaHX5GXE0xHRcW29NmaGq8UbcEmTTxc5EgbBNS/Tfai71HGaO0VmrA
|
||||
P6SbNMrgSAlfap1caLQ8CcUASDqEf+BcjZhgetddqSL2KLkL5ot7IxOS2blzQH/I
|
||||
Jk/2Boi36yQ5JoLPbs/TRAV4wHMci3B9ZNHQrdcqP2zl0zC64eNt5fNgo+F/iH/z
|
||||
2M32O+V3HpOJDvFtSC+Q9Ux3kOC4/dmembZex8IPAGJ4IfCyL3cwJYUCAwEAAaNC
|
||||
MEAwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFMpi
|
||||
L3tJgzuP+QDY3uyx99aMAB0sMA0GCSqGSIb3DQEBCwUAA4IBAQCO1OS0DYntM4ut
|
||||
ZNZIkJA+SAFKy06IAev3o9wBiOzlIM5rVm4TDa0L7qFH/Z2l9bRmWDqDeba281qZ
|
||||
EIFGJI1QPAWX47RbQXJOTOIiGsNoUw4swt6it+NoemARwZAoGPYOXqXLVknXalR5
|
||||
ye33OaoI0EowrHw01sv72mbEqeWhb9XKw3h1UkbfdkZIG9KiftYVAlPUNUSaSy8n
|
||||
ApKbqEw2CcRjSPjeLeS9zbLSj+M20NYlwU56xaxIm64TRk65Ac17PN5KJiOHYuDp
|
||||
1fnHqnbPbOOMdfhuRU1D48sSZlAKFiR3p0vLkSNwfmJmWRTfWuAUNAA339CRTKOb
|
||||
Ge9OTWOZ
|
||||
-----END CERTIFICATE-----
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
FileAssets:
|
||||
- content: |
|
||||
apiVersion: kubescheduler.config.k8s.io/v1beta2
|
||||
clientConnection:
|
||||
kubeconfig: /var/lib/kube-scheduler/kubeconfig
|
||||
kind: KubeSchedulerConfiguration
|
||||
path: /var/lib/kube-scheduler/config.yaml
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
apiserver-aggregator-ca: "7142721951056419283723637893"
|
||||
etcd-clients-ca: "7142721951028761584467841211"
|
||||
etcd-manager-ca-events: "7142721951057921435241405328"
|
||||
etcd-manager-ca-main: "7142721951074386633614158554"
|
||||
etcd-peers-ca-events: "7142721951138880539659455124"
|
||||
etcd-peers-ca-main: "7142721951056140991529806803"
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
service-account: "7142721951191621691964241737"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
kops.k8s.io/instancegroup: master-ap-northeast-2b
|
||||
kops.k8s.io/kops-controller-pki: ""
|
||||
node-role.kubernetes.io/control-plane: ""
|
||||
node.kubernetes.io/exclude-from-external-load-balancers: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
registerSchedulable: false
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
etcdManifests:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/manifests/etcd/main-master-ap-northeast-2b.yaml
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/manifests/etcd/events-master-ap-northeast-2b.yaml
|
||||
staticManifests:
|
||||
- key: kube-apiserver-healthcheck
|
||||
path: manifests/static/kube-apiserver-healthcheck.yaml
|
||||
useInstanceIDForNodeName: true
|
||||
@@ -0,0 +1,288 @@
|
||||
APIServerConfig:
|
||||
KubeAPIServer:
|
||||
allowPrivileged: true
|
||||
anonymousAuth: false
|
||||
apiAudiences:
|
||||
- kubernetes.svc.default
|
||||
apiServerCount: 3
|
||||
authorizationMode: Node,RBAC
|
||||
bindAddress: 0.0.0.0
|
||||
cloudProvider: external
|
||||
enableAdmissionPlugins:
|
||||
- NamespaceLifecycle
|
||||
- LimitRanger
|
||||
- ServiceAccount
|
||||
- DefaultStorageClass
|
||||
- DefaultTolerationSeconds
|
||||
- MutatingAdmissionWebhook
|
||||
- ValidatingAdmissionWebhook
|
||||
- NodeRestriction
|
||||
- ResourceQuota
|
||||
etcdServers:
|
||||
- https://127.0.0.1:4001
|
||||
etcdServersOverrides:
|
||||
- /events#https://127.0.0.1:4002
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
image: registry.k8s.io/kube-apiserver:v1.25.2@sha256:86e7b79379dddf58d7b7189d02ca96cc7e07d18efa4eb42adcaa4cf94531b96e
|
||||
kubeletPreferredAddressTypes:
|
||||
- InternalIP
|
||||
- Hostname
|
||||
- ExternalIP
|
||||
logLevel: 2
|
||||
requestheaderAllowedNames:
|
||||
- aggregator
|
||||
requestheaderExtraHeaderPrefixes:
|
||||
- X-Remote-Extra-
|
||||
requestheaderGroupHeaders:
|
||||
- X-Remote-Group
|
||||
requestheaderUsernameHeaders:
|
||||
- X-Remote-User
|
||||
securePort: 443
|
||||
serviceAccountIssuer: https://api.internal.dev.datasaker.io
|
||||
serviceAccountJWKSURI: https://api.internal.dev.datasaker.io/openid/v1/jwks
|
||||
serviceClusterIPRange: 100.64.0.0/13
|
||||
storageBackend: etcd3
|
||||
ServiceAccountPublicKeys: |
|
||||
-----BEGIN RSA PUBLIC KEY-----
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4UK3R2fjYWGtlIJU3nBS
|
||||
UTIX9Eg+vp9Uw4zMhkz1K5BnyB2IsKR0F9LnMdLaTrF7Zo1Bef82Ew80eKS0JwY5
|
||||
NOj+ZP9FiC7bVRRdeuW5KMGjEmhWSz/mVahxgo0pRE9xP3yA2Ij1lQjn3R0Yr6ec
|
||||
E+fwjAF2o93L+KpBzcXrpGiPa0+Qx1I8VPKLyLjM/SfK3eBUcouNbWeGi8+DULAf
|
||||
DHMUA7B6U+w/IbEd3kVCTSWEBK+R2CAl8sIMZ424wGnNX58G4yy2uGYlcOItTZzU
|
||||
fPt9ulI1DYvycFTkPzedFu+KF5GlulcqMqmPRANWDSj26gDmahVoraO0eQ9vCDhp
|
||||
vwIDAQAB
|
||||
-----END RSA PUBLIC KEY-----
|
||||
Assets:
|
||||
amd64:
|
||||
- 631e31b3ec648f920292fdc1bde46053cca5d5c71d622678d86907d556efaea3@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubelet
|
||||
- 8639f2b9c33d38910d706171ce3d25be9b19fc139d0e3d4627f38ce84f9040eb@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/amd64/kubectl
|
||||
- 962100bbc4baeaaa5748cdbfce941f756b1531c2eadb290129401498bfac21e7@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-amd64-v0.9.1.tgz
|
||||
- 3a1322c18ee5ff4b9bd5af6b7b30c923a3eab8af1df05554f530ef8e2b24ac5e@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-amd64.tar.gz
|
||||
- db772be63147a4e747b4fe286c7c16a2edc4a8458bd3092ea46aaee77750e8ce@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.amd64
|
||||
- 8f01da0b6bf77d36b28840186c5387ecda831036d0d671805b6a5367bdd1b284@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/protokube,https://github.com/kubernetes/kops/releases/download/v1.25.0/protokube-linux-amd64
|
||||
- 7ba778d62bbca3ec158c62279713ef774f695f341e264ea572a0b7cbdd022071@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/amd64/channels,https://github.com/kubernetes/kops/releases/download/v1.25.0/channels-linux-amd64
|
||||
arm64:
|
||||
- c9348c0bae1d723a39235fc041053d9453be6b517082f066b3a089c3edbdd2ae@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubelet
|
||||
- b26aa656194545699471278ad899a90b1ea9408d35f6c65e3a46831b9c063fd5@https://storage.googleapis.com/kubernetes-release/release/v1.25.2/bin/linux/arm64/kubectl
|
||||
- ef17764ffd6cdcb16d76401bac1db6acc050c9b088f1be5efa0e094ea3b01df0@https://storage.googleapis.com/k8s-artifacts-cni/release/v0.9.1/cni-plugins-linux-arm64-v0.9.1.tgz
|
||||
- b114e36ecce78cef9d611416c01b784a420928c82766d6df7dc02b10d9da94cd@https://github.com/containerd/containerd/releases/download/v1.6.8/containerd-1.6.8-linux-arm64.tar.gz
|
||||
- dbb71e737eaef454a406ce21fd021bd8f1b35afb7635016745992bbd7c17a223@https://github.com/opencontainers/runc/releases/download/v1.1.4/runc.arm64
|
||||
- dead6a79da3a04785c25b03fef625b3d220bf77e2b0750b525023c48a70f4081@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/protokube,https://github.com/kubernetes/kops/releases/download/v1.25.0/protokube-linux-arm64
|
||||
- 609d23833768046d3626eba1c8dd620ce86d7235bbe3073f4c6241f26c31e456@https://artifacts.k8s.io/binaries/kops/1.25.0/linux/arm64/channels,https://github.com/kubernetes/kops/releases/download/v1.25.0/channels-linux-arm64
|
||||
CAs:
|
||||
apiserver-aggregator-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDDDCCAfSgAwIBAgIMFxRSNNb6vi6f8FSFMA0GCSqGSIb3DQEBCwUAMCIxIDAe
|
||||
BgNVBAMTF2FwaXNlcnZlci1hZ2dyZWdhdG9yLWNhMB4XDTIyMDkxMTA0NDkwOVoX
|
||||
DTMyMDkxMDA0NDkwOVowIjEgMB4GA1UEAxMXYXBpc2VydmVyLWFnZ3JlZ2F0b3It
|
||||
Y2EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC2CwCYipJHeykxywc/
|
||||
wcAZQzTt49XYDHsTnMPtdSkF4Qdy+cwRi1SpL5cpO9ByqGwZ7exXKhe6EAOhfmmG
|
||||
yZgDvI95434tp6a64mbBmCrR+4NIKDIkoXIrhEGogbJlDij/K63yVCAZCPulyj7G
|
||||
VyE7X4bEmvuAbYDeJheX+ZFGhV5iLS2fri13NMEp9a9nms22V9hJitLxzV3LLdl5
|
||||
db/q3LMb96xl27ccbcSyz5gEuKJfvKqEb7bCVg6yJbdbVO+CMLpnIMFsiXwwSyO0
|
||||
xXrCzyeNHAB9eK/n0gGkWb/RKoLqXTUNdGu4SvaPYnTJKAT2eHvBNAlPt5rJO5Kt
|
||||
Yz4xAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0G
|
||||
A1UdDgQWBBT1GhQw65WfbiDWTeUx5k1xHMz/ajANBgkqhkiG9w0BAQsFAAOCAQEA
|
||||
Uih4ajNq0Yys9IFBziOT+W2rxdodQOzcJpXWTdSNnxRzOtasjiYUoGdzdizT54Y4
|
||||
wjtWnBGgB+sre3pTF8TNnv/AlBLx8t0ANOifcncPLRFsBtJVDFCuglPXrn5cHDOr
|
||||
anLTIzQ3etoDV/h2AQxQafYUg9ZtwgyEbou7kwLi+p9TBJdV3iWowfdgs9HtHagd
|
||||
wL0/v6RU8pojl7hBYIloGB1AIREDSfprxDMzUBDyOY7uyvcfK+RcUoLRuq6Tq2ob
|
||||
PsOtl3ZaSTOmdQ0r8SEUMtOm0jozbyRu9ojq7/+UOu3yT1YeM4M7N6lYNtZx153O
|
||||
ILB6F+I/dTp9EdI/qBNrqg==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-clients-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC/DCCAeSgAwIBAgIMFxRSNNaYe6a0fhC7MA0GCSqGSIb3DQEBCwUAMBoxGDAW
|
||||
BgNVBAMTD2V0Y2QtY2xpZW50cy1jYTAeFw0yMjA5MTEwNDQ5MDlaFw0zMjA5MTAw
|
||||
NDQ5MDlaMBoxGDAWBgNVBAMTD2V0Y2QtY2xpZW50cy1jYTCCASIwDQYJKoZIhvcN
|
||||
AQEBBQADggEPADCCAQoCggEBAJdTYAp2rgiShljdkdR/P1kt81okDYl1q+/6rUS4
|
||||
L8AwJDtbIIvQcmgRgoR3mlhRBQIibeHSWHNlt99TYzkUeQF8n2cE3MJbSNmykGqf
|
||||
A8CxluTyL32TDnsRbonQoDK5wKbWpCFD1KD7P/aozOdsoDlPV18Y46dZ4j3Yv2C1
|
||||
ppaUmv0hQ62eLeDXQlq1e7VFmwiij/lsW/bNXI6r/ENFRbCsfhCCY5xkoOeWPrFJ
|
||||
ci68UbzQssmR0xlcGbCtcxfwmsPi0C9Php5mtpmRWa9uTGbSK3ZD1jx98S2OWWVe
|
||||
1jiCmIyzsqY31QioOveWaCL14JqArO2FqrugXx2ZxAI1OSkCAwEAAaNCMEAwDgYD
|
||||
VR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFA4wbacZ59AB
|
||||
n3dc7WLWkb9TF+CUMA0GCSqGSIb3DQEBCwUAA4IBAQBQn+1DUIZOkgTwUmW3Nnt8
|
||||
sWUV7NRy3ZdB9lEbWWwodNRheYMEHUe8y/Z2VvWiYNKA9K0lVYpu0MGF6HiClqhN
|
||||
FWU7eFv6uVGf2ypBNTy5cz+PNYAfxl9U4gBGJRKzuKOICFHp7laKzBuiwk934Daa
|
||||
xeZeA+7Pt23o52APhXVXTKf3U5v/97e631rOfnE+o9D6mL3XnWj5vZ4/1moQD1nm
|
||||
eyRJXT1LaKULk52o52c4O6FIgniit746qyakIllhUk5vMsnlXTjO2v16iyi2i62z
|
||||
jhx8pJzZ2phPBcSjDR+Bm4WbAKvZjAUFQ6MjgqXxxTDtGy52erAzXmjLeqBsHrvi
|
||||
-----END CERTIFICATE-----
|
||||
etcd-manager-ca-events: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDCjCCAfKgAwIBAgIMFxRSNNcAFGGHjduQMA0GCSqGSIb3DQEBCwUAMCExHzAd
|
||||
BgNVBAMTFmV0Y2QtbWFuYWdlci1jYS1ldmVudHMwHhcNMjIwOTExMDQ0OTA5WhcN
|
||||
MzIwOTEwMDQ0OTA5WjAhMR8wHQYDVQQDExZldGNkLW1hbmFnZXItY2EtZXZlbnRz
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3KRK8906XyxKwYZcISZO
|
||||
uEYgQ2WGAZNQXgvxbb5GBAM4f9Pv0JuoAL0uy9qpyqQDq6ACe5jICyvg3+9LU+pW
|
||||
GDxubYHb6f15BJtw36zO6Mgs5BTjrW9zxjJSzZIoGDL7zw+d7B7bASAfuIWZfmmm
|
||||
lMQg/pnywbG1jPTB1rEVOryOHMXntXe6C/CpxTZz66AYYd6+7GrCLC8uHG5PyEie
|
||||
tv7avgRb06RKJQSJ3reGRHJ8UI9bJduTlaQyZpCmfxpqnK7E57SFSuzbcYi/iMGY
|
||||
GUZCfR8tLtsMjDYTxsTCvBQWuVP3FJXS1KKoyfgfQ4AvNhzo/I5K9ZGGb24CvtzZ
|
||||
+QIDAQABo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
|
||||
HQ4EFgQU0pBv8lYo6UyaXEX7P7KPMEIll1kwDQYJKoZIhvcNAQELBQADggEBAG7C
|
||||
vDSF0dAEyThlrhzpUBZX6dLWwRtsGqXmsqS7TTvSExiDxl+27llAVVb6DIg5b3Lp
|
||||
fa4P5cDcflFaNsWz/vCwkB9yoiUm2tCqxRkr1LKY9FIV/FUGwE5imr7HyGmpcbKh
|
||||
xCC+57ZHXuZj7oZsBoTyCVjj+PX6UmqsTMG6GEOuvDvrzqKI1h3WSMtovRjLUmCX
|
||||
cPrwOJJoKzy1gWCNsILSwFmSyklsjIzVFliXp+Si0IHwHwqmVn9JEnz64A5C5nkB
|
||||
jBOFXTznDiPWOmNc2RYumSpNl0srm5fqR9FA21H4DOJI4VmpK8YWwSmwNmmwAZoS
|
||||
XOkBupErXPmZkj/8CEk=
|
||||
-----END CERTIFICATE-----
|
||||
etcd-manager-ca-main: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDBjCCAe6gAwIBAgIMFxRSNNc6k2RDt+raMA0GCSqGSIb3DQEBCwUAMB8xHTAb
|
||||
BgNVBAMTFGV0Y2QtbWFuYWdlci1jYS1tYWluMB4XDTIyMDkxMTA0NDkwOVoXDTMy
|
||||
MDkxMDA0NDkwOVowHzEdMBsGA1UEAxMUZXRjZC1tYW5hZ2VyLWNhLW1haW4wggEi
|
||||
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChc/xsdUXOfkMw/TiONzQ5ymzO
|
||||
4i7seuBYgbBriR1n0PyCFoAmNXMvVt+JtytvBzr0FfPnpjpO+xb+L1MY2m7Rbx4F
|
||||
5brrJN1LwFlZOQjKCpgxOUT+EFVneXvmZx7E0UbJ+TxEGGOZ1N6t1mxdmsdjO0TV
|
||||
mhMg6Nawj1+HAQsdgkMDAWv3PEgUeJCrRg+7KzBQxY0pOVuZkeQZ+MHsR3GLdIZn
|
||||
l3h13ePS6Z1K+Uz4VMR4myV1wXFyOR1Qms7ROZ3wIiCoE/Vqg9bn70funi4PMG0l
|
||||
/Bxj9t2ogMOla7ypNzcwjNRtzhdmuAaEvdrvZ6XF4NXWM8DpjiR9dA3Y0dffAgMB
|
||||
AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
|
||||
BBTD5SaTxIzni41qVldUtl9SqcBM7TANBgkqhkiG9w0BAQsFAAOCAQEANyBp0bU4
|
||||
gJrgLLnjKC/atTvHRzCrLmHz9ECa9bN9I6dAsiyJmxGPPlD+PkhFNxzenQ80VizD
|
||||
qo+w9RQGDtfMD5WX0A8M4KN5A8efTBhWReI9lzxGaRxUwQRiKXBRgn778nFZ7E/5
|
||||
9DmDlibhdb1XEz0X+l6XkNyJdHHsCPi2omKRY6R9W7+/ezvkH6mqAcTC7DufWB77
|
||||
T3sr6lmFR69isQB0kQlhXG/Ws+g6zN7CyRP741sQAPWYfRaziLYSTcdnFHMBNRHc
|
||||
zm3DVnbPCrjV7zjSdoNbPgPvEvZYGMSnK0tfxhYKTVRT8cKWlBBwnPYMKW/O0ED0
|
||||
Z2RjK1J0AFawFQ==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-peers-ca-events: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDBjCCAe6gAwIBAgIMFxRSNNgftEHrucqUMA0GCSqGSIb3DQEBCwUAMB8xHTAb
|
||||
BgNVBAMTFGV0Y2QtcGVlcnMtY2EtZXZlbnRzMB4XDTIyMDkxMTA0NDkwOVoXDTMy
|
||||
MDkxMDA0NDkwOVowHzEdMBsGA1UEAxMUZXRjZC1wZWVycy1jYS1ldmVudHMwggEi
|
||||
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDAA6jobVkkVeddp9oTaVMbthfB
|
||||
dforGm4J/E3KBBmA5+3HXknFZ+nXAK0naZUS2RrHUrigTcux1no1Om3eTJCcxmOR
|
||||
IIFYAjX3vpMXhOMCgh98U/BrN96xdaRPRNF5lwluc26ZLRcS7Y+HeZwORCB0auX4
|
||||
5XZFb72CT2kfWaqnsum7YC/r/aJzUS1dIrGZwKBYCZct3TfCZTzW4aL6rkHdrriJ
|
||||
KNIaV1FR/n6X2hdTpVnHou/mk5Zr0WYz1YaAlJIqHJEavrYIjLp6pWgsho8ESB+D
|
||||
WHEm+cHNVFMuVm++5OWr5PZNLawD44MUomH/DlTVK0B9qdS3gQ6X4Hx6gDS3AgMB
|
||||
AAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQW
|
||||
BBRozlb1pjT7aWt9Kg70JkqBH6y4BzANBgkqhkiG9w0BAQsFAAOCAQEApP3tYKOy
|
||||
hy2AGVeTOfh5YSKuSQQJjyy5mBuHIpB0vYcukSABn+60n7Ku4hAGERucscBjHpWy
|
||||
55BBRDjVvY1jlB4AJKRmlAlGngmwhz9KO86EvxXzJaDfxd92rDY1iOF3DM9UNUCI
|
||||
vlvVA1ws7XhWLlUPZf+Ndpj7s1ar46htDy0ONchhXiokzNcDqNtMgSZzS1+WJY+n
|
||||
n5BjbIO91sQqLsd4DHLVi9ZWcr4LyS9hYSFPSNAPOnNsGnj3WcWTcctH8yUxhzwZ
|
||||
1Cty74gyfTtTENm5dZk+wAjkxTkixO+18NG0PCXos/1FONthR521u3qqLXSZNYL0
|
||||
u1zeRMpGpRYUtA==
|
||||
-----END CERTIFICATE-----
|
||||
etcd-peers-ca-main: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDAjCCAeqgAwIBAgIMFxRSNNb5wROslOvTMA0GCSqGSIb3DQEBCwUAMB0xGzAZ
|
||||
BgNVBAMTEmV0Y2QtcGVlcnMtY2EtbWFpbjAeFw0yMjA5MTEwNDQ5MDlaFw0zMjA5
|
||||
MTAwNDQ5MDlaMB0xGzAZBgNVBAMTEmV0Y2QtcGVlcnMtY2EtbWFpbjCCASIwDQYJ
|
||||
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAMN1BKqeJVUBLg1gS8GIZzld/MG8Xgod
|
||||
F4DQKxYYVI9mmkEpP5nhesYQ8qnnqW6js9URF5GXUoaeiaM/krigc4yYm7YRts7B
|
||||
Lzbd6Mlfo8LaHX5GXE0xHRcW29NmaGq8UbcEmTTxc5EgbBNS/Tfai71HGaO0VmrA
|
||||
P6SbNMrgSAlfap1caLQ8CcUASDqEf+BcjZhgetddqSL2KLkL5ot7IxOS2blzQH/I
|
||||
Jk/2Boi36yQ5JoLPbs/TRAV4wHMci3B9ZNHQrdcqP2zl0zC64eNt5fNgo+F/iH/z
|
||||
2M32O+V3HpOJDvFtSC+Q9Ux3kOC4/dmembZex8IPAGJ4IfCyL3cwJYUCAwEAAaNC
|
||||
MEAwDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFMpi
|
||||
L3tJgzuP+QDY3uyx99aMAB0sMA0GCSqGSIb3DQEBCwUAA4IBAQCO1OS0DYntM4ut
|
||||
ZNZIkJA+SAFKy06IAev3o9wBiOzlIM5rVm4TDa0L7qFH/Z2l9bRmWDqDeba281qZ
|
||||
EIFGJI1QPAWX47RbQXJOTOIiGsNoUw4swt6it+NoemARwZAoGPYOXqXLVknXalR5
|
||||
ye33OaoI0EowrHw01sv72mbEqeWhb9XKw3h1UkbfdkZIG9KiftYVAlPUNUSaSy8n
|
||||
ApKbqEw2CcRjSPjeLeS9zbLSj+M20NYlwU56xaxIm64TRk65Ac17PN5KJiOHYuDp
|
||||
1fnHqnbPbOOMdfhuRU1D48sSZlAKFiR3p0vLkSNwfmJmWRTfWuAUNAA339CRTKOb
|
||||
Ge9OTWOZ
|
||||
-----END CERTIFICATE-----
|
||||
kubernetes-ca: |
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC+DCCAeCgAwIBAgIMFxRSNNnsf/9iL637MA0GCSqGSIb3DQEBCwUAMBgxFjAU
|
||||
BgNVBAMTDWt1YmVybmV0ZXMtY2EwHhcNMjIwOTExMDQ0OTA5WhcNMzIwOTEwMDQ0
|
||||
OTA5WjAYMRYwFAYDVQQDEw1rdWJlcm5ldGVzLWNhMIIBIjANBgkqhkiG9w0BAQEF
|
||||
AAOCAQ8AMIIBCgKCAQEAuWlsK26NCl/z8mUJ0hVq8a6CxuhhZO76ZKxza4gjpNSZ
|
||||
hrnC1kyQed8zjDln2APE20OE2or6nEWmjWWZJkr3wToQygFDj/5SuL4WwF1V2Fcz
|
||||
iaHcLz9oFva/EgJfWgZ/W/aaXWJRNsFVN8CAt1Z43wEZwmbKjykQ83IUIng3/z3t
|
||||
/eRAx1wc+3ahMqbZD7hOCihCKbaNc3FGzPOvu/1AC/6TyxV/nwqfaroW5MbC3/Dt
|
||||
UmrZJk5titRTG8aU9i7ZviMLAuHd8nZBzjIeqp95AdAv6nMVV9RveRz64Yip/B4Z
|
||||
h0GMczJ8VmXQN8Dq6xz4eE7Hx0962Y+xQklEan1vfQIDAQABo0IwQDAOBgNVHQ8B
|
||||
Af8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUa5SJcwBuRj6rJ2OL
|
||||
hEsmhX/nGcQwDQYJKoZIhvcNAQELBQADggEBABtVPrhKPIFuPM8uQbQHGC2AV7Ap
|
||||
afIKWHx2gXtf3uDfBe52Xa2WI/nExnQE+MM0iFU3Bgq1aYe9/rJmkptZJuD6vfkz
|
||||
VWhuIGGkyxYSxsuBo8UYdzsWpSzP8dH3Mip3PNNS3F3bcU3z5uufuOZUmdIn+NPS
|
||||
qgBgxpqCVy/KzRVp30sM4uj9i6bXB/CioE1oUssPchrB8uWV+THZEfle1TSgK9sg
|
||||
jFx1R0mqhxH/eW6UsHJPgf14mdjEGiimaamvWcY7CjhuFwYog42ltgrgW9HzMtJM
|
||||
cEc9lRITKurTr0TWW+x1yDeCaKd/1ZGjFVtQMUYyV+GAfKsAOtDCUPGF9dA=
|
||||
-----END CERTIFICATE-----
|
||||
ClusterName: dev.datasaker.io
|
||||
FileAssets:
|
||||
- content: |
|
||||
apiVersion: kubescheduler.config.k8s.io/v1beta2
|
||||
clientConnection:
|
||||
kubeconfig: /var/lib/kube-scheduler/kubeconfig
|
||||
kind: KubeSchedulerConfiguration
|
||||
path: /var/lib/kube-scheduler/config.yaml
|
||||
Hooks:
|
||||
- null
|
||||
- null
|
||||
KeypairIDs:
|
||||
apiserver-aggregator-ca: "7142721951056419283723637893"
|
||||
etcd-clients-ca: "7142721951028761584467841211"
|
||||
etcd-manager-ca-events: "7142721951057921435241405328"
|
||||
etcd-manager-ca-main: "7142721951074386633614158554"
|
||||
etcd-peers-ca-events: "7142721951138880539659455124"
|
||||
etcd-peers-ca-main: "7142721951056140991529806803"
|
||||
kubernetes-ca: "7142721951268583043543051771"
|
||||
service-account: "7142721951191621691964241737"
|
||||
KubeletConfig:
|
||||
anonymousAuth: false
|
||||
cgroupDriver: systemd
|
||||
cgroupRoot: /
|
||||
cloudProvider: external
|
||||
clusterDNS: 100.64.0.10
|
||||
clusterDomain: cluster.local
|
||||
enableDebuggingHandlers: true
|
||||
evictionHard: memory.available<100Mi,nodefs.available<10%,nodefs.inodesFree<5%,imagefs.available<10%,imagefs.inodesFree<5%
|
||||
featureGates:
|
||||
CSIMigrationAWS: "true"
|
||||
InTreePluginAWSUnregister: "true"
|
||||
kubeconfigPath: /var/lib/kubelet/kubeconfig
|
||||
logLevel: 2
|
||||
nodeLabels:
|
||||
kops.k8s.io/instancegroup: master-ap-northeast-2c
|
||||
kops.k8s.io/kops-controller-pki: ""
|
||||
node-role.kubernetes.io/control-plane: ""
|
||||
node.kubernetes.io/exclude-from-external-load-balancers: ""
|
||||
podInfraContainerImage: registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db
|
||||
podManifestPath: /etc/kubernetes/manifests
|
||||
protectKernelDefaults: true
|
||||
registerSchedulable: false
|
||||
shutdownGracePeriod: 30s
|
||||
shutdownGracePeriodCriticalPods: 10s
|
||||
UpdatePolicy: automatic
|
||||
channels:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/addons/bootstrap-channel.yaml
|
||||
containerdConfig:
|
||||
configOverride: |
|
||||
version = 2
|
||||
imports = ["/etc/containerd/runtime_*.toml"]
|
||||
|
||||
[plugins]
|
||||
[plugins."io.containerd.grpc.v1.cri"]
|
||||
sandbox_image = "registry.k8s.io/pause:3.6@sha256:3d380ca8864549e74af4b29c10f9cb0956236dfb01c40ca076fb6c37253234db"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc]
|
||||
runtime_type = "io.containerd.runc.v2"
|
||||
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options]
|
||||
SystemdCgroup = true
|
||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."registry-1.docker.io".auth]
|
||||
username = "datasaker"
|
||||
password = "dckr_pat_kQP6vcHm_jMChWd_zvgH_G3kucc"
|
||||
logLevel: info
|
||||
runc:
|
||||
version: 1.1.4
|
||||
version: 1.6.8
|
||||
etcdManifests:
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/manifests/etcd/main-master-ap-northeast-2c.yaml
|
||||
- s3://clusters.dev.datasaker.io/dev.datasaker.io/manifests/etcd/events-master-ap-northeast-2c.yaml
|
||||
staticManifests:
|
||||
- key: kube-apiserver-healthcheck
|
||||
path: manifests/static/kube-apiserver-healthcheck.yaml
|
||||
useInstanceIDForNodeName: true
|
||||
2842
aws_total/terraform/tf-kops-dev-20221025/kubernetes.tf
Normal file
2842
aws_total/terraform/tf-kops-dev-20221025/kubernetes.tf
Normal file
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user